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Preface 



Logics have, for many years, laid claim to providing a formal basis for the study of 
artificial intelligence. With the depth and maturity of methodologies, formalisms, 
procedures, implementations, and their applications available today, this claim is 
stronger than ever, as witnessed by increasing amount and range of publications 
in the area, to which the present proceedings accrue. 

The European series of Workshops on Logics in Artificial Intelligence (or 
Journees Europeennes sur la Logique en Intelligence Artificielle - JELIA) began 
in response to the need for a European forum for the discussion of emerging 
work in this burgeoning field. JELIA 2000 is the seventh such workshop in the 
series, following the ones held in Roscoff, France (1988); Amsterdam, Netherlands 
(1990); Berlin, Germany (1992); York, U.K. (1994); Evora, Portugal (1996); and 
Dagstuhl, Germany (1998). 

JELIA 2000 will take place in Malaga, Spain, from 29 September to 2 Oc- 
tober 2000. The workshop is organized and hosted by the Research Group of 
Mathematics Applied to Gomputing of the Department of Applied Mathematics 
of the University of Malaga. 

As in previous workshops, the aim is to bring together researchers involved in 
all aspects of logic in artificial intelligence. Additional sponsorship was provided 
by the ESPRIT NOE Gompulog-Net. 

This volume contains the papers selected for presentation at the workshop 
along with abstracts and papers from the invited speakers. The programme 
committee selected these 23 papers, from 12 countries (Australia, Austria, Bel- 
gium, Ganada, Finland, Germany, Hong Kong, Italy, The Netherlands, Portu- 
gal, Spain, and the United Kingdom), out of 60 submissions, from 22 countries 
(submissions were also received from Argentina, Brazil, Gzech Republic, France, 
Japan, Mexico, Poland, Slovakia, Sweden, and Switzerland). We would like to 
thank all authors for their contributions as well as the invited speakers Johan 
van Benthem from the University of Amsterdam (The Netherlands), Thomas 
Eiter from the Vienna University of Technology (Austria), Reiner Hahnle from 
the Ghalmers University of Technology (Sweden), and Frank Wolter from the 
University of Leipzig (Germany). 

Papers were reviewed by the programme committee members with the help 
of the additional referees listed overleaf. We would like thank them all for their 
valuable assistance. It is planned that a selection of extended versions of the 
best papers will be published in the journal Studia Logica, after being subjected 
again to peer review. 

September 2000 Gerd Brewka 

Inma P. de Guzman 
Manuel Ojeda- Aciego 
Luis Moniz Pereira 
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‘On Being Informed’: Update Logics for 
Knowledge States 



Johan van Benthem 
ILLC Amsterdam 

http : //www. taring, wins .uva.nl/~johEm/ 



Statements convey information, by modifying knowledge states of hearers and 
speakers. This dynamic aspect of communication goes beyond the usual role of 
logic as a provider of static ’truth conditions’. But it can be modelled rather 
nicely in so-called ’update logics’, which have been developed since the 1980s. 
These systems provide a fresh look at standard logic, letting the usual models 
undergo suitable changes as agents absorb the content of successive utterances or 
messages. This lecture is a brief Whig history of update logics, with an empha- 
sis on many-agent epistemic languages. We discuss straight update, questions 
and answers, and the delightful complexities of communication under various 
constraints. We hope to convey the attraction of giving a dynamic twist to well- 
known things, such as simple modal models, or basic epistemic formulas. 



M. Ojeda-Aciego et al. (Eds.): JELIA2000, LNAI 1919, pp. 1-1, 2000. 
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Considerations on Updates of Logic Programs 



Thomas Eiter, Michael Fink, Giuliana Sabbatini, and Hans Tompits 



Institut und Ludwig Wittgenstein Labor fiir Informationssysteme, TU Wien 
Favoritenstrafie 9-11, A- 1040 Wien, Austria 
{eiter ,michael, giulicuia, tompits }@kr .tuwien. ac . at 



Abstract. Among others, Alferes et al. (1998) presented an approach 
for updating logic programs with sets of rules based on dynamic logic 
programs. We syntactically redehne dynamic logic programs and investi- 
gate their semantical properties, looking at them from perspectives such 
as a belief revision and abstract consequence relation view. Since the ap- 
proach does not respect minimality of change, we refine its stable model 
semantics and present minimal stable models and strict stable models. 
We also compare the update approach to related work, and hnd that is 
equivalent to a class of inheritance programs independently defined by 
Buccafurri et al. (1999). 



1 Introduction 

In recent years, agent-based computing has gained increasing interest. The need 
for software agents that behave “intelligently” in their environment led to ques- 
tion for possibilities of equipping them with advanced reasoning capabilities. 

The research on logic-based Al, and in particular the work on logic program- 
ming, has produced a number of approaches and methods from which we can 
take advantage for accomplishing this goal (see e.g. [11]). It has been realized, 
however, that further work is needed for extending them to fully support that 
agents must adapt over time and adjust their decision making. 

In a simple (but as for currently deployed agent systems, realistic) setting, an 
agent’s knowledge base KB may be modeled as a logic program. The agent may 
now be prompted to adjust its KB after receiving new information in terms of an 
update U, which is a clause or a set of clauses that need to be incorporated into 
KB. Simply adding the rules of U to KB does not give a satisfactory solution 
in practice, and will result in inconsistency even in simple cases. For example, if 
KB contains the rule a ^ and U consists of the rule not a ^ stating that a 
is not provable, then the union KB U C/ is not consistent under stable semantics 
(naturally generalized to programs with default negation in rule heads [21]), 
which is the predominating two- valued semantics for declarative logic programs. 

Most recently, several approaches for updating logic programs with (sets of) 
rules have been presented [2,5,17,13]. In particular, the concept of dynamic logic 
programs by Alferes et al., introduced in [2] and further developed in [3,5,4,20], 
has attracted a lot of interest. Their approach has its roots, and generalizes. 



M. Ojeda-Aciego et al. (Eds.): JELIA2000, LNAI 1919, pp. 2-20, 2000. 
© Springer- Verlag Berlin Heidelberg 2000 
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the idea of revision programming [22], and provides the basis for LUPS, a logic- 
programming based update specification language [5] . The basic idea behind the 
approach is that in case of conflicting rules, a rule r in [/ (which is assumed to 
be correct as of the time of the update request) is more reliable than any rule r' 
in KB. Thus, application of r rejects application of r' . In the previous example, 
the rule not a <— from U rejects the rule a <— from KB, thus resolving the 
conflict by adopting that a is not provable. The idea is naturally extended to 
sequences of updates U\, . . . ,Un by considering the rules in more recent updates 
as more reliable. 

While uses and extensions of dynamic logic programming have been dis- 
cussed, cf. [5,4,20], its properties and relationships to other approaches and re- 
lated formalisms have been less explored (but see [4]). The aim of this paper is to 
shed light on these issues, and help us to get a better understanding of dynamic 
logic programming and related approaches in logic programming. 

The main contributions of our work can be summarized as follows. 

— We syntactically redefine dynamic logic programs to equivalent update pro- 
grams, for which stable models are defined. Update programs are slightly 
less involved and, as we believe, better reflect the working of the approach 
than the original definition of dynamic logic programs. For this, information 
about rule rejection is explicitly represented at the object level through re- 
jection atoms. The syntactic redefinition, which reduces the type of rules in 
update programs, is helpful for establishing formal results about properties. 

— We investigate properties of update programs. We consider them from the 
perspective of belief revision, and review different sets of postulates that 
have been proposed in this area. We view update programs as nonmonotonic 
consequence operators, and consider further properties of general interest. 
As it turns out, update programs (and thus dynamic logic programs) do 
not satisfy many of the properties defined in the literature. This is partly 
explained by the nonmonotonicity of logic programs and the causal rejection 
principle embodied in the semantics, which strongly depends on the syntax 
of rules. 

— Dynamic logic programs make no attempt to respect minimality of change. 
We thus refine the semantics of update programs and introduce minimal 
stable models and strict stable models. Informally, minimal stable models 
minimize the set of rules that need to be rejected, and strict stable models 
further refine on this by assigning rules from a later update higher priority. 

— We compare update programs to alternative approaches for updating logic 
programs [13,17] and related work on inheritance programs [9]. We And that 
update programs are equivalent to a class of inheritance programs. Thus, up- 
date programs (and dynamic logic programs) may be semantically regarded 
as fragment of the framework in [9], which has been developed independently 
of [2,5]. Our results on the semantical properties of update programs apply 
to this fragment as well. 

Due to space reasons, the presentation is necessarily succinct and proofs are 
omitted. More details will be given in the full version of this paper. 
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2 Preliminaries 

Generalized logic programs [21] consist of rules built over a set A of propositional 
atoms where default negation not is available. A literal, L, is either an atom A 
(a positive literal) or the negation not A of an atom A (a negative literal, also 
called default literal). For a literal L, the complementary literal, noth, is not A 
A L = A, and A A L = not A, for some atom A. For a set S of literals, not S is 
given by not S = {not L \ L e S}. We also denote by Litj\ the set A U not A of 
all literals over A. 

A rule, r, is a clause of the form Lq ^ Li, . . . , L„, where n > 0 and Lq may 
be missing, and each (0 < z < n) is a default literal, i.e., either an atom A 
or a negated atom not A. We call Lq the head of r and the set {Li, . . . , L„} the 
body of r. The head of r will also be denoted by H{r), and the body of r will be 
denoted by B(r). If the rule r has an empty head, then r is a constraint] if the 
body of r is empty and the head is non-empty, then r is a fact. We say that r 
has a negative head if H{r) = not A, for some atom A. The set B~^(r) comprises 
the positive literals of B{r), whilst B~{r) contains all default literals of B{r). 

By we denote the set of all rules over the set A of atoms. We will usually 
write C instead of if the underlying set A is fixed. A generalized logic program 
(GLP) P over A is a finite subset of Cj\. If no rule in P contains a negative 
head, then P is a normal logic program (NLP); if no default negation whatsoever 
occurs in P, then P is a positive program. 

By an (Herbrand) interpretation we understand any subset I C A. The 
relation / ^ L for a literal L is defined as follows: 

~ if P = A is an atom, then / |= A iff A G /; 

~ if P = not A is a default literal, then I ^ not A iff / [P A. 

If / ^ P, then / is a model of P, and P is said to be true in I (if / [P P, then P 
is false in I). For a set S of literals, / ^ S' iff / ^ P for all P G S'. Accordingly, 
we say that / is a model of S. Furthermore, for a rule r, we define / ^ r iff 
I ^ H(r) whenever / ^ B{r). In particular, if r is a contraint, then / |= r iff 
I [P B{r). In both cases, if / ^ r, then I is a model of r. Finally, / |= P for a 
program P iff / |= r for all r G P. 

If a positive logic program P has some model, it has always a smallest Her- 
brand model, which we will denote by lm{P). If P has no model, for technical 
reasons it is convenient to set lm{P) = Lit a. 

We define the reduct, P^ , of a generalized program P w.r.t. to an Herbrand 
interpretation / as follows. P^ results from P by 

1. deleting any rule r in P such that either I \= B~{r), or / ^ H{r) if H{r) = 
not A for some atom A; and 

2. replacing any remaining rule r by A , where A = H{r) <— B'^{r) if H{r) is 
positive, and = <— B'^{r) otherwise {A is called the reduct of r). 

Observe that P^ is a positive program, hence lm{P^) is well-defined. We say 
that / is a stable model of P iff lm{P^) = I. By S{P) we denote the set of all 
stable models of P. A program is satisfiable if S{P) A 
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We regard a logic program P as the epistemic state of an agent. The given 
semantics is used for assigning a belief state to any epistemic state P in the 
following way. 

Let / C ^ be an Herbrand interpretation. Define 

BeU{I) = {r G I / h r}. 

Furthermore, for a class X of interpretations, define Bel^{X) = Hiei BeUil). 

Definition 2.1. For a logic program P, the belief state, Belj^{P), of P is given 
by Bel_A{P) = Belj\^{S{P)), where S{P) is the collection of all stable models 
ofP. 

We write P \=_a r if r G Belj\{P)- As well, for any program Q, we write P \=_a Q 
if P [=_A. q for all q G Q. Two programs, P\ and P 2 , are equivalent (modulo the 
set A), symbolically P\ P 2 , iff Beljx{Pi) = Belji,{P 2 ). Usually we will drop 
the subscript “A” in Belj,{-), \=Aj and =a if no ambiguity can arise. 

An alternative for defining the belief state would consist in considering brave 
rather than cautious inference, which we omit here. 

Belief states enjoy the following natural properties: 

Theorem 2.1. For every logic program P, we have that: 

1. PC Bel{P); 

2. Bel{Bel{P)) = Bel{P); 

3. {r I / 1= r, for every interpretation 1} C Bel{P). 

Clearly, the belief operator Bel{-) is nonmonotonic, i.e., in general P\ C P 2 
does not imply Bel{P\) C Bel{P 2 ). 

3 Update Programs 

We introduce a framework for update programs which simplifies the approach 
introduced in [2]. By an update sequence, P, we understand a series Pi, . . . , P„ 
of general logic programs where each Pi is assumed to update the information 
expressed by the initial section Pi, ... , Pi-\. This update sequence is translated 
into a single program P' representing the update information given by P. The 
“intended” stable models of P are identified with the stable models of P' (modulo 
the original language) . 

Let P = Pi , . . . , P„ be an update sequence over a set of atoms A. We assume 
a set of atoms A* extending A by new, pairwise distinct atoms rej{-), Ai, and 
A~ , where A G A and 1 < z < n. Furthermore, we assume an injective naming 
function which assigns to each rule r in a program Pi a distinguished 

name, N{r,Pi), obeying the condition N{r,Pi) yf N{r',Pj) whenever i yf j. 
With a slight abuse of notation we shall identify r with N{r,Pi) as usual. 

Definition 3.1. Given an update sequence P = P\, ... ,Pn over a set of atoms 
A we define the update program P<| = Pi < . . . < P„ over A* consisting of the 
following items: 
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1. all constraints in Pi, I <i <n; 

2. for each r G Pi, 1 < i < n: 

Ai ^ B{r), not rej (r) if H{r) = A; 

A~ ^ B{r), not rej (r) if PI (r) = not A; 

3. for each r G Pi, 1 < i < n: 

rej (r) ^ B{r), A~^^ if H (r) = A; 

rej(r) ^ B(r),Ai+i if H{r) = not A; 

4- for each atom A occurring in P {1 <i < n): 

A^ <— <— A ^ Ai; <— 

Informally, this program expresses layered derivability of an atom ^ or a 
literal not A, beginning at the top layer Pn downwards to the bottom layer Pi . 
The rule r at layer Pi is only applicable if it is not refuted by a literal L that is 
incompatible with P[ (r) derived at a higher level. Inertia rules propagate a locally 
derived value for A downwards to the first level, where the local value is made 
global; the constraint ^ Ai,Af is used here in place of the rule not A ^ Af . 

Similar to the transformation given in [2], P<| is modular in the sense that 
the transformation for P' = Pi, . . . , P„, P„+i augments P<| = Pi < . . . < P„ only 
with rules depending on n + 1 . 

We remark that P<| can obviously be slightly simplified, which is relevant for 
implementing our approach. All literals not rej (r) in rules with heads A„ or A~ 
can be removed: since rej (r) cannot be derived, they evaluate to true in each 
stable model of P<|. Thus, no rule from P„ is rejected in a stable model of P<|, 
i.e., all most recent rules are obeyed. 

The intended models of an update sequence P = Pi , . . . , P„ are defined in 
terms of the stable models of P<| . 

Definition 3.2. Let P = Pi, . . . , P„ be an update sequence over a set of atoms 
A. Then, S C A is an {update) stable model of P iff S = S' D A for some stable 
model S' of P<| . The collection of all update stable models of P is denoted by 
U{P). 

Following the case of single programs, an update sequence P = Pi, . . . , P„ is 
regarded as the epistemic state of an agent, and the belief state Bel{P) is given 
by Bel{U{P)). As well, the update sequence P is satisfiable iff U{P) yf 0. 

To illustrate Definition 3.2, consider the following example, taken from [2]. 

Example 3.1. Consider the update of Pi by P 2 , where 

Pi = { ri : sleep ^ not tv-on, V 2 : tv-on ^ : watchAv ^ tv-on }; 

P 2 = { i "4 : not tv-on ^ power-failure, : power-failure <— } . 
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The single stable model of P = Pi, P2 is, as desired, S = {power-failure, sleep}, 
since S' is the only stable model of P<|: 



S'' = { power-failure 2 , power-failurei , power -failure, 
tv-onf , tv-onf , rej (r 2 ) , sleepi , sleep } . 



If new information arrives in form of the program P3 : 

P 3 = { i "6 '■ not power-failure ^ } , 

then the update sequence Pi, P2, P3 has the stable model T = {tv-on, watch-tv}, 
generated by the model T' of Pi < P2 < P3: 

P' = { power-failuref , power-failuref , power -failuref , 
rej{r^), tv-orii, tv-on, watch-tvi, watch-tv }. 



Next, we discuss some properties of our approach. The first result guarantees 
that stable models of P are uniquely determined by the stable models of P<| . 



Theorem 3.1. Let P = P\, ... ,Pn he an update sequence over a set of atoms 
A, and let S, T be stable models of P<| . Then, S n .4 = P n .4 only if S = T. 

If an update sequence P consists of a single program, the notion of update 
stable models of P and regular stable models of P coincide. 



Theorem 3.2. Let P be an update sequence consistinq of a sinqle proqram Pi, 
i.e., P = Pi. Then, U{P) = S(Pi). 



Stable models of update sequences can also be characterized in a purely 
declarative way. To this end, we introduce the following concept. 

For an update sequence P = Pi , . . . , P„ over a set of atoms A and S' C yl, we 
define the rejection set of S by Rej (S, P) = [ff-i Rej^{S, P), where Rej^{S, P) = 
0 , and, for n > i > 1, 

Rej^{S, P) = {r G Pi \ 3r' G P,- \ Pep (S, P), for some j G {t + 1 , . . . , n}, 
such that H{r') = not H{r) and S h B{r) U B{r')}. 

That is, Rej (S, P) contains those rules from P which are rejected on the basis 
of rules which are not rejected themselves. 

We obtain the following characterization of stable models, mirroring a similar 
result given in [2]. 

Theorem 3.3. Let P = Pi, ... ,Pn be an update sequence over a set of atoms 
A, and let S C A. Then, S is a stable model of P iff S = lm{{P \ Rej{S, P))^). 
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4 Principles of Update Sequences 

In this section, we discuss several kinds of postulates which have been advocated 
in the literature on belief change and examine to what extent update sequences 
satisfy these principles. This issue has not been addressed extensively in previ- 
ous work [2,3]. We first consider update programs from the perspective of belief 
revision, and assess the relevant postulates from this area. Afterwards, we briefly 
analyze further properties, like viewing update programs as nonmonotonic con- 
sequence operators and other general principles. 

4.1 Belief Revision 

Following [14], two different approaches to belief revision can be distinguished: 
(i) immediate revision, where the new information is simply added to the current 
stock of beliefs and the belief change is accomplished through the semantics of 
the underlying (often, nonmonotonic) logic; and (ii) logic- constrained revision, 
where the new stock of beliefs is determined by a nontrivial operation which 
adds and retracts beliefs, respecting logical inference and some constraints. 

In the latter approach, it is assumed that beliefs are sentences from some 
given logical language Cb which is closed under the standard boolean connec- 
tives. A belief set, K, is a subset of which is closed under a consequence 
operator Cn{-) of the underlying logic. A belief base for AT is a subset B C K 
such that K = Cn{B). A belief base is a special case of an epistemic state [10], 
which is a set of sentences E representing an associated belief set K in terms of 
a mapping Bel{-) such that K = Bel{E), where E need not necessarily have the 
same language as K. 

In what follows, we first introduce different classes of postulates, and then 
we examine them with respect to update sequences. 



AGM Postulates One of the main aims of logic-constrained revision is to char- 
acterize suitable revision operators through postulates. Alchourron, Gardenfors, 
and Makinson (AGM) [1] considered three basic operations on a belief set K: 

— expansion K -\- <j>, which is simply adding the new information <f> £ Cb to K] 

— revision K -k <f>, which is sensibly revising K in the light of (j) (in particular, 
when K contradicts 4>); and 

— contraction K — <j), which is removing (j) from K. 

AGM presented a set of postulates, K*l-K*8, that any revision operator * map- 
ping a belief set A C Cb and a sentence (j> € Cb into the revised belief set 
K -k(j) should satisfy. If, following [10,8], we assume that K is represented by an 
epistemic state E, then the postulates K*l-K*8 can be reformulated as follows: 

(Kl) E k (j) represents a belief set. 

(K2) (j>e BellEk(j>). 

(K3) Bel{Ek(j3) C Bel{E + (/)). 
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(K4) ^(j) ^ Bel{E) implies Bel{E + </)) C Bel{E ★ (j)). 

(K5) _L G Bel{E -k (j)) iff (j) is unsatisfiable. 

(K6) (j)i = (j >2 implies Bel{E k (pi) = Bel{E k cp 2 ). 

(K7) Bel{E k{(PA r/>)) C Bel{{E k (P) + iP). 

(K8) ^(p ^ Bel{E k (p) implies Bel{{E k p) + ip) ^ Bel{E k (p A p)). 

Here, Ekp and E+p is the revision and expansion operation, respectively, ap- 
plied to E. Informally, these postulates express that the new information should 
be reflected after the revision, and that the belief set should change as little 
as possible. As has been pointed, this set of postulates is appropriate for new 
information about an unchanged world, but not for incorporation of a change to 
the actual world. Such a mechanism is addressed by the next set of postulates, 
expressing update operations. 



Update Postulates For update operators Bop realizing a change ptoa, belief 
base B, Katsuno and Mendelzon [18] proposed a set of postulates, U*l-U*8, 
where both p and B are propositional sentences over a finitary language. For 
epistemic states E, these postulates can be reformulated as follows. 

(Ul) p e Bel{EoP). 

(U2) p G Bel{E) implies Bel(Eop) = Bel{E). 

(U3) If Bel{E) is consistent and p is satisfiable, then Bel{E o p) is consistent. 
(U4) If Bel{E) = Bel(E') and p = p, then Bel{E o p) = Bel{E o p). 

(U5) Bel{E o {p A p)) C Bel{{E o p) + p). 

(U6) If p G Bel{E o p) and p G Bel{E o p), then Bel{E o p) = Bel{E o p). 
(U7) If Bel{E) is complete, then Bel{Eo{p\J p')) C Bel{E op) A Bel{E op'))} 
(U8) Bel{{E V E') op) = Bel{{E o V’) V {E' o P). 

Here, conjunction and disjunction of epistemic states are presumed to be 
definable in the given language (like, e.g., in terms of intersection and union of 
associated sets of models, respectively). 

The most important differences between (K1)-(K8) and (U1)-(U8) are that 
revision, if p is compatible with E, should yield the same result as expansion 
E + p, which is not desirable for update in general, cf. [24] . On the other hand, 
(U8) says that if E can be decomposed into a disjunction of states (e.g., models), 
then each case can be updated separately and the overall results are formed by 
taking the disjunction of the emerging states. 



Iterated Revision Darwiche and Pearl [10] have proposed postulates for iter- 
ated revision, which can be rephrased in our setting as follows (we omit paren- 
theses in sequences {E k pi) k p 2 of revisions): 

(Cl) If p 2 G Bel{pi), then Bel{E kp 2 k pi) = Bel{E k pi). 

(C2) If -'■02 G Bel{pi), then Bel{E kpik P 2 ) = Bel{E k P 2 ). 



^ A belief set K is complete iff, for each atom A, either A G K ot —•A G K. 
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(C3) If tp 2 G Bel{E then %p 2 G Bel{E * V’2 * V'l)- 

(C4) If ^'ip 2 ^ Bel{E * 'ipi), then ^'ip 2 ^ Bel{E * -02 * V’l)- 

(C5) If -i'02 G Bel{E -k ‘ipi) and ipi ^ Bel{E * 1 P 2 ), then ipi ^ Bel{E * 0i * 02)- 

(C6) If ^02 G Bel(Ek'tpi) and ->0i G i?el(if*02), then -i0i G *0i *02). 

Another set of postulates for iterated revision, corresponding to a sequence 
E of observations, has been formulated by Lehmann [19]. Here each observation 
is a sentence which is assumed to be consistent (i.e., falsity is not observed), and 
the epistemic state E has an associated belief set Bel{E). Lehmann’s postulates 
read as follows, where E, E' denote sequences of observations and stands for 
concatenation: 

(11) Bel{E) is a consistent belief set. 

(12) (j)€ Bel{E,(l,). 

(13) If 0 G Bel{E, 0), then <j) ^ 'ij^ & Bel{E). 

(14) If 0 G Bel{E), then Bel{E, 0, E') = Bel{E, E). 

(15) If 0 h 0 then Bel{E, 0, 0, E') = Bel{E, 0, E'). 

(16) If -10 ^ Bel{E, 0), then Bel{E, 0, 0, E') = Bel{E, 0, 0, E'). 

(17) Bel{E, ^0, 0) C Cn{E + 0). 



Analysis of the Postulates In order to evaluate the different postulates, we 
need to adapt them for the setting of update programs. Naturally, the epistemic 
state P = Pi,...,P„ of an agent is subject to revision. However, the associ- 
ated belief set Bel{P) (C does not belong to a logical language closed 
under boolean connectives. Closing >C_4 under conjunction does not cause much 
troubles, as the identification of finite GLPs with finite conjunctions of clauses 
permits that updates of a CLP P by a program Pi can be viewed as the update 
of P with a single sentence from the underlying belief language. Ambiguities 
arise, however, with the interpretation of expansion, as well as the meaning of 
negation and disjunction of rules and programs, respectively. 

Depending on whether the particular structure of the epistemic state E 
should be respected, different definitions of expansion are imaginable in our 
framework. At the “extensional” level of sentences, represented by a program 
or sequence of programs P, Bel{P + P') is defined as Bel{Bel{P) U P'). At 
the “intensional” level of sequences P = Pi,...,P„, Bel{P + P') could be 
defined as Bel{Pi , . . . , U P'). An intermediate approach would be defining 
Bel{P + P') = Belji{P^ U P'). We adopt the extensional view here. Note that, 
in general, adding P' to Bel{P) does not amount to the semantical intersection 
of P' and Bel{P) (nor of P and P' , respectively). 

As for negation, we might interpret the condition ^0 ^ Bel{E) (or —•ip (p 
Bel{Ek(p) in (K4) and (K8)) as satisfiability requirement for E+(j> (or (A*0)-|-0). 

Disjunction V of rules or programs (as epistemic states) appears to be mean- 
ingful only at the semantical level. The union S{Pi) US{P 2 ) of the sets of stable 
models of programs Pi and P 2 may be represented syntactically through a pro- 
gram P3, which in general requests an extended set of atoms. We thus do not 
consider the postulates involving V. 
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Postulate 


Interpretation 


Postulate holds 


(Kl) 


(Pi, P2) represents a belief set 


yes 


(K2), (Ul) 


P2 C Bel{Pi,P 2 ) 


yes 


(U2) 


Bel{P 2 ) C Bel{Pi) implies Bel{Pi, P 2 ) ~ Bel{P\) 


no 


(K3) 


Bel\Pi,P 2 ) C Bel{Bel{Pi) U P2) 


yes 


(U3) 


If Pi and p2 are satisfiable, then (Pi, P2) is satisfiable 


no 


(K4) 


If Bel{Pi) U P2 has a stable model, then 
Bel{Bel{Pi) U P2) C Bel{Pi,P 2 ) 


no 


(K5) 


(Pi,P2) is unsatisfiable iff P2 is unsatisfiable 


no 


(K6), (U4) 


Pi = Pi' and P2 = Pj implies (Pi, P2) = (P(, P2) 


no 


(K7), (U5) 


Pe;(Pi,P2 UP3) C Bel{Bel{Pi,P 2 )Al P3) 


yes 


(U6) 


If Pef(Ps) C Bel{Pi,P 2 ) and Bel{P 2 ) C PeZ(Pi,Ps), 
then Bel{Pi, P 2 ) = Bel{Pi, P3) 


no 


(K8) 


If Bel{Pi, P 2 ) U P3 is satisfiable then 
Bel{Bel{Pi, P 2 ) U P3) C Bd{Pi, P 2 U P3) 


no 



Table 1. Interpretation of Postulates (K1)-(K8) and (U1)-(U6). 



Given these considerations, Table 1 summarizes our interpretation of postu- 
lates (K1)~(K8) and (U1)-(U6), together with indicating whether the respective 
property holds or fails. We assume that P\ is a nonempty sequence of GLPs. 

Thus, apart from very simple postulates, the majority of the adapted AGM 
and update postulates are violated by update programs. This holds even for the 
case where P\ is a single program. In particular, Bel{Pi, P 2 ) violates discrimi- 
nating postulates such as (U2) for update and (K4) for revision. In the light of 
this, update programs neither have update nor revision flavor. 

We remark that the picture does not change if we abandon extensional expan- 
sion and consider the postulates under intensional expansion. Thus, also under 
this view, update programs do not satisfy minimality of change. 

The postulates (G1)-(G6) and (I1)“(I7) for iterated revision are treated in 
Table 2. Goncerning Lehmann’s [19] postulates, (13) is considered as the pendant 
to AGM postulate K*3. In a literal interpretation of (13), we may, since the 
belief language associated with GLPs does not have implication, consider the 
case where V’ is a default literal Lq and (p = Li A ■ ■ ■ A Lk is a, conjunction of 
literals Li, such that (p ^ ip corresponds to the rule Lq ^ L\, . . . , L^. Since the 
negation of GLPs is not defined, we do not interpret (17). 

Note that, although postulate (G3) fails in general, it holds if P 3 contains a 
single rule. Thus, all of the above postulates except G4 fail, already if P\ is a 
single logic program, and, with the exception of G3, each change is given by a 
single rule. 

A question at this point is whether, after all, the various belief change pos- 
tulates from above are meaningful for update programs. 

We can view the epistemic state P = P\, ... ,Pn of an agent as a prioritized 
belief base in the spirit of [7,23,6]. Revision with a new piece of information Q is 
accomplished by simply changing the epistemic state to P = P\, . . . ,Pn,Q. The 
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Postulate 


Interpretation 


Postulate holds 


(Cl) 


If Ps C Bel{P2), then Bel{Pi,P 3 , P2) = PeZ(Pi, P2) 


no 


(C 2 ) 


If S' Pa, for all S G S(P2), then Bel{Pi, Ps, P2) = 
Bel{Pi,P2) 


no 


(C 3 ) 


If Pa C Bel{Pi,P2), then Pa C Bel{Pi,P 3 , P2) 


no 


(C 4 ) 


If S ^ Pa for some S G S(Pi, P2), then S ^ P3 for 
some S G S(Pi, Pa, P2) 


yes 


(C 5 ) 


If S Pa for all S G S(Pi, P2) and P2 g Bel(Pi, Pa), 
then P2 g Bel{P\, P2, Pz) 


no 


(C6) 


If S Pa for all S G S{Pi,P2) and S P2 for all 

S G S(Pi, Pa), then S ^ P2 for all S G S(Pi, P2, P3) 


no 


(11) 


Bel (Pi) is a consistent belief set 


no 


(12) 


P2 gPeZ(Pi,P2) 


yes 


( 13 ) 


If Lo ^ e Bel{Pi, {Li, . . . , I/fc}), then 
Lq < — Li, . . . , Lk ^ 


yes 


( 14 ) 


If P2 g Bel{Pi), then 

Bel{Pi, p2, Pa, . . . , Pn) = Bel(Pi, P3, . . . , Pn) 


no 


( 15 ) 


If BeliPs) g Bel{P2), then 

Bel{Pi, p2, P3, P4, . . . , Pn)~Bel{Pi, P3, P4, . . . , Pn) 


no 


( 16 ) 


If S 1 = P3 for some S G S(Pi, P2), then 
Bel{Pi, p2, Pa, Pi , . . . , Pn) = Bel{P\, P2, P2U 
Pa, Pi,. . . , Pn) 


no 



Table 2. Interpretation of Postulates (C1)-(C6) and (I1)-(I6). 



change of the belief base is then automatically accomplished by the nonmono- 
tonic semantics of a sequence of logic programs. Under this view, updating logic 
programs amounts to an instance of the immediate revision approach. 

On the other hand, referring to the update program, we may view the belief 
set of the agent represented through a pair (P, A) of a logic program P and 
a (fixed) set of atoms A, such that its belief set is given by Beljx{P). Under 
this view, a new piece of information Q is incorporated into the belief set by 
producing a representation, (P',A), of the new belief set, where P' = P <\Q. 
Here, (a set of) sentences from an extended belief language is used to characterize 
the new belief state, which is constructed by a nontrivial operation employing the 
semantics of logic programs. Thus, update programs enjoy to some extent also 
a logic-constrained revision flavor. Nonetheless, as also the failure of postulates 
shows, they are more an instance of immediate than logic- eonstrained revision. 
What we naturally expect, though, is that the two views described above amount 
to the same at a technical level. However, as we shall demonstrate below, this is 
not true in general. 

4.2 Further Properties 

Belief revision has been related in [14] to nonmonotonic logics by interpreting it 
as an abstract consequence relation on sentences, where the epistemic state is 
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fixed. In the same way, we can interpret update programs as abstract consequence 
relation S' on programs as follows. For a fixed epistemic state P and GLPs P\ 
and P2, we define 



P\ K'p P2 if and only if P2 C Bel{P, Pi), 

i.e., if the rules P2 are in the belief state of the agent after update of the epistemic 
state with Pi. 

Various properties for nonmonotonic inference operations have been identi- 
fied in the literature (see, e.g., [ 14 ]). Among them are Cautious Monotonicity, 
Cut, {Left) Conjunction, Rational Cautious Monotonicity, and Equivalence. Ex- 
cept for Cut, none of these properties hold. We recall that Cut denotes the 
following schema: 

A^Bl^...^Bmt^ pC AC p Bl^...^Bm 
ACpC 

Additionally, we can also identify some very elemental properties which, as 
we believe, updates and sequences of updates should satisfy. The following list of 
properties is not developed in a systematic manner, though, and is by no means 
exhaustive. Update programs do enjoy, unless stated otherwise, these properties. 

Addition of Tautologies: If the program P2 contains only tautological clauses, 
then {Pi,P2) = Pi- 

Initialization: ( 0 , P) = P. 

Idempotence: {P, P) = P. 

Idempotence for Sequences: {Pi, P2, P2) = {Pi,P2)- 

Update of Disjoint Programs: If P = Pi U P2 is a union of programs Pi, P2 
on disjoint alphabets, then (P, P3) = (Pi,P3) U {P2,Ps). 

Parallel updates: If P2 and P3 are programs defined over disjoint alphabets, 
then (Pi,P2) U (Pi,P3) = (Pi,P2 U P3). {Fails.) 

Noninterference: If P2 and P3 are programs defined over disjoint alphabets, 
then {Pi,P2,Ps) = (Pi,P3,P2). 

Augmented update: If P2 C P3 then {Pi, P2, P3) = {Pi,Ps). 

As mentioned before, a sequence of updates P = Pi , . . . , P„ can be viewed 
from the point of view of “immediate” revision or of “logic-constrained” re- 
vision. The following property, which deserves particular attention, expresses 
equivalence of these views (the property is formulated for the case n = 3 ) : 

Iterativity: For any epistemic state Pi and GLPs P2 and P3, it holds that 
Pi < P2 < P3 (Pi < P2) < P3. 

However, this property fails. Informally, soundness of this property would 
mean that a sequence of three updates is a shorthand for iterated update of a 
single program, i.e., the result of Pi <P2 is viewed as a singleton sequence. Stated 
another way, this property would mean that the definition for Pi < P2 < P3 can 
be viewed as a shorthand for the nested case. Vice versa, this property reads as 




14 



Thomas Eiter et al. 



possibility to forget an update once and for all, by incorporating it immediately 
into the current belief set. 

For a concrete counterexample, consider Pi = 0 , P2 = {a <— , not a ^ }, 
-P3 = {a ^ }. The program <\ P2 <\ P3 has a unique stable model, in 

which a is true. On the other hand, (Pi <P2) <Pa has no stable model. Informally, 
while the “local” inconsistency of P2 is removed in Pi < P2 < P3 by rejection of 
the rule not a ^ via P3, a similar rejection in (Pi < P2) < P3 is blocked because 
of a renaming of the predicates in Pi < P2. The local inconsistency of P2 is thus 
not eliminated. 

However, under certain conditions, which exclude such possibilities for local 
inconsistencies, the iterativity property holds, given by the following result: 

Theorem 4.1. Let P = Pi, . . . ,P„, n > 2 , be an update sequence on a set of 
atoms A. Suppose that, for any rules r\,r2 G Pi, i < n, such that H{ri) = 
not H{r2), the union B{ri) U B{r2) of their bodies is unsatisfiable. Then: 

(• • • (Pi < P2) < P3) • • • < P„-i) < P„ Pi < P2 < P3 < • • • < Pn- 

5 Refined Semantics and Extensions 

Minimal and Strict Stable Models Even if we abandon the AGM view, 
update programs do intuitively not respect minimality of change, as a new set 
of rules P2 should be incorporated into an existing program Pi with as little 
change as possible. 

It appears natural to measure change in terms of the set of rules in Pi which 
are abandoned. This leads us to prefer a stable model S'! of P = Pi,P2 over 
another stable model S2 if S\ satisfies a larger set of rules from Pi than S2 ■ 

Definition 5.1. Let P = Pi,...,P„ be a sequence of GLPs. A stable model 
S G U{P) is minimal iff there is no T & ^{P) such that Rej{T,P) C Rej{S,P). 



Example 5 . 1 . Consider Pi = {ri : not a ^ }, P2 = {?'2 : a ^ note}, and 
-F3 = {i"3 ■ c ^ notd, T4 : d <— note }. Then (Pi,P2) has the single stable 
model {a}, which rejects the rule in Pi. The sequence (Pi, P2, P3) has two stable 
models: Si = {c} and S2 = {a,d}. Si rejects no rule, while S2 rejects the rule 
ri. Thus, Si is preferred to S2 and Si is minimal. 

Minimal stable models put no further emphasis on the temporal order of 
updates. Rules in more recent updates may be violated in order to satisfy rules 
from previous updates. Eliminating this leads us to the following notion. 

Definition 5 . 2 . Let S, S' G 11 {P) for an update sequence P = Pi, . . . , P„. Then, 
S is preferred to S' iff some i G {!,..., n} exists such that ( 1 ) Reji{S,P) C 
Rejii. 3 ' , P), and ( 2 ) Rejj{S', P) = Rej j{S, P), for all j = i + 1 , . . . ,n. A stable 
model S of P is strict, if no S' G U{P) exists which is preferred to S. 
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Example 5.2. Consider P = Pi, P2, P3, P4, where P\ = {ri : not a ^ }, P2 = 
{t 2 : a ^ not c}, P3 = {rs : not c ^ } , and P4 = {t4 : c ^ not d, 
rs : d ^ not c }. Then, P has two stable models, namely Si = {c} and S2 = 
{a,d}. We have Rej{Si,P) = {rs} and Rej{S2,P) = {fi}. Thus, Rej{Si,P) 
and Rej{S2, P) are incomparable, and hence both Si and S2 are minimal stable 
models. However, compared to S2 in Si the more recent rule of P3 is violated. 
Thus, S2 is the unique strict stable model. 

Clearly every strict stable model is minimal, but not vice versa. Unsurpris- 
ingly, minimal and strict stable models do not satisfy ACM minimality of change. 

The trade-off for epistemic appeal is higher computational complexity than 
for arbitrary stable models. Let Belmin{P) (resp., Belstr{P)) be the set of 
beliefs induced by the collection of minimal (resp., strict) stable models of 
P = Pi, ■ ■ ■ ,Pn- 

Theorem 5 . 1 . Given a sequence of programs P = Pi, P2, ..., Pn over a set of 
atoms A, deciding whether 

1. P has a stable model is AV -complete; 

2. L G Bel{P) for a given literal L is coAV -complete; 

3. L G Belmin{P) {resp. L G Belstr{P)) for a given literal L is II2 -complete. 

Similar results have been derived by Inoue and Sakama [ 17 ]. The complexity 
results imply that minimal and strict stable models can be polynomially trans- 
lated into disjunctive logic programming, which is currently under investigation. 

Strong Negation Update programs can be easily extended to the setting of 
generalized extended logic programs (GELPs), which have besides not also 
strong negation ^ as in [ 21 ]. Viewing, for A G A, the formula ^A as a fresh 
atom, the rules not A <— ^A and not ^A <— A emulate the interpretation of 
^ in answer set semantics (cf., e.g., [ 2 ]). More precisely, the consistent answer 
sets of a GELP P correspond one-to-one to the stable models of P^ , which is P 
augmented with the emulation rules for ^A. Answer sets of a sequence of GELPs 
P = Pi, ..., Pn can then be defined through this correspondence in terms of the 
stable models of P~' = Pf, . . ., Pf^, such that Bel{P) = Bel(P^). 

Like for dynamic logic programs [ 3 ] , P^ can be simplified by removing some 
of the emulation rules. Let CR{P) be the set of all emulation rules for atoms A 
such that ~^A occurs in some rule head of P. 

Theorem 5 . 2 . For any sequence of GELPs P = Pi,. . . ,Pn over A, S' C A U 
{^A I A G A} is an answer set of P iff S G Id {Pi , . . . , P„_i, Pn U CR{P)). 

First-Order Programs The semantics of a sequence P = Pi, ... ,Pn oi first- 
order GLPs, i.e., where A consists of nonground atoms in a first order-language, 
is reduced to the ground case by defining it in terms of the sequence of instanti- 
ated programs P* = Pf , . . . , P* over the Herbrand universe of P as usual. That 
is, U{P) — U{P*). The definition of update program P^ can be easily general- 
ized to non-ground programs, such that P^ = P* <1, i.e., P^ faithfully represents 
the update program for P* . 
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6 Related Work 

Dynamic Logic Programming Recall that our update programs syntactically 
redefine dynamic logic programs for update in [2,5], which generalize the idea of 
updating interpretations through revision programs [22]. As we feel, they more 
transparently reflect the working behind this approach. 

The major difference between our update programs and dynamic logic pro- 
grams is that the latter determine the values of atoms from the bottom level P\ 
upwards towards P„, using interia rules, while update programs determine the 
values in a downward fashion. 

Denote by ©P = Pi © • • • © Pn the dynamic logic program of [2] for updating 
Pi with P 2 , . . . , P„ over atoms A, which is a GLP over atoms Adyn 2 A. For 
any model M of P„ in A, let 

Rejected{M, P) = lj”=i{^ G Pi I 3r' G Pj, for some j G {z + 1, . . . , n}, such 

that H{r') = not H{r) A S' ^ P(r) U P(r')}, 
Defaults{M, P) = {not A | Vr G P : H{r) = A M [A P(r)}. 

Stable models of ©P, projected to A, are semantically characterized as follows. 

Definition 6.1. For a sequence P = Pi,...,P„ of GLPs over atoms A, an 
interpretation N C Adyn is a stable model of ©P iff M = N C\ A is a model of 
U such that 



M = lm{P \ Rejected{M, P) U Defaults{M, P)). 

Here, literals not A are considered as new atoms, where implicitly the constraint 
^ A, not A is added. Let us call any such M a dynamic stable model of P. 

As one can see, we may replace Rej{S, P) in Theorem 3.3 by Rejected{S, P) 
and add all rules in Defaults{S, P), as they vanish in the reduction by S. How- 
ever, this implies that update and dynamic stable models coincide. 

Theorem 6.1. For any sequence P = Pi, . . . , P„ of GLPs over atoms A, S C A 
is a dynamic stable model of P iff S G ld{P). 

Inheritance Programs A framework for logic programs with inheritance is 
introduced in [9] . In a hierarchy of objects oi , . . . , o„, represented by a disjunctive 
extended logic program Pi,...,P„ [15], possible conflicts in determining the 
properties of Oi are resolved by favoring rules which are more specific according 
to the hierarchy, which is given by a (strict) partial order < over the objects. 

If we identify Oi with the indexed program P^, an inheritance program consists 
of a set P = {Pi, . . . , P„} of programs over atoms A and a partial order < on 
P. The program V{Pi) for Pi (as an object) is given by P(Pi) = {Pi} U {Pj \ 
Pi < Pj}, i.e., the collection of programs at and above Pi. 

The semantics of P(Pi) is defined in terms of answer sets. In the rest of this 
section, we assume that any program P^ G P is disjunction-free and we simplify 
definitions in [9] accordingly. Let, for each literal L of form A or ^A, denote 
its opposite, and let Litjx = A LI {^A \ Ag A}. 
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Definition 6.2. Let I C Lit a be an interpretation and r G Pj. Then, r is 
overridden in I, if (1) I |= B{r), (2) ^H{r) G I, and (3) there exists a rule 
fi G Pi for some Pi < Pj such that H{r\) = -^H{r). 

An interpretation / C Lit a is a model of 7^, if / satisfies all non-overridden 
rules in V and the constraint <— A, not A for each atom A G A; moreover, / is 
minimal if it is the least model of all these rules. Answer sets are now as follows. 

Definition 6.3. A model M of V = V{Pi), is a DLP"^ -answer set ofV iff M 
is a minimal model ofV^, where = {r gV \ r is not overridden in M}^ 
is the reduct ofV by M . 

It is natural to view an update sequence P = Pi , . . . , as an inheritance 
program where later updates are considered more specific. That is, we might 
view P as an inheritance program P„ < P„_i < . . . < Pi. It appears that the 
latter is in fact equivalent to the update program Pi < . . . < P„. 

For a sequence of GLPs P = Pi , . . . , P„ over A, define the inheritance pro- 
gram Q = Qn < Qn-i < ■ ■ ■ < Qi as follows. Let P~ be the program resulting 
from Pi by replacing in rule heads the default negation not through Define 
Qi = Pf U {^A ^ not A \ A G A} and Qj = P~ , for j = 2, . . . , n. Then we 
have the following. 

Theorem 6.2. Let P = P\, ... ,Pn be a sequence of GLPs over atoms A. Then, 
S G U{P) iff S U {^A I A G A \ S'} is a DLP"^ -answer set of Q(Pi, . . . , P„). 

Conversely, linear inheritance programs yield the same result as update pro- 
grams in the extension with classical negation. 

Theorem 6.3. Let P = P\ < ■ • • < P„ be an inheritance program over atoms 
A. Then, S is a DLP^ -answer set of P iff S is an answer set of the sequence of 
GELPs Pn, Pn-l, • ■ • ) Pi • 

Thus, dynamic logic programs and inheritance programs are equivalent. 



Program Updates through Abduction On the basis of their notion of ex- 
tended abduction, Inoue and Sakama [17] define a framework for various update 
problems. The most general is theory update, which is update of an extended logic 
program (ELP) Pi by another such program P 2 . Informally, an abductive update 
of Pi by P 2 is a largest consistent program P' such that P\ Q P' Q Pi UP 2 holds. 
This is formally captured in [17] by reducing the update problem to computing 
a minimal set of abducible rules Q Q P\\P 2 such that (Pi U P 2 ) \ Q is consistent. 
In terms of [16], Pi UP 2 is considered for abduction where the rules in Pi \P 2 are 
abducible, and the intended update is realized via a minimal anti- explanation 
for falsity, which removes abducible rules to restore consistency. 

While this looks similar to our minimal updates, there is a salient difference: 
abductive update does not respect causal rejection. A rule r from Pi \ P 2 may 
be rejected even if no rule r' P 2 fires whose head contradicts applying r. For 
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example, consider = {g <— , ^ a} and P 2 = {a ^ }. Both Pi and 

P2 have consistent answer sets, while (Pi,P2) has no stable model. In Inoue 
and Sakama’s approach, one of the two rules in Pi will be removed. Note that 
contradiction removal in a program P occurs as a special case (Pi = P, P2 = 0). 

Abductive updates are, due to inherent minimality of change, harder than 
update programs; some abductive reasoning problems are Pl^-complete [17]. 

Updates through Priorities Zhang and Foo [13] define update of an ELP Pi 
by an ELP P 2 based on their work on preferences [12] as a two-step approach: In 
Step 1, each answer set S of Pi is updated to a closest answer set S' of P 2 , where 
distance is in terms of the set of atoms on which S,S' disagree and closeness is 
set inclusion. Then, a maximal set Q C Pi is chosen such that P3 = P2 U Q has 
an answer set containing S' . In Step 2, the answer sets of P3 are computed using 
priorities, where rules of P2 have higher priority than rules of Q. 

This approach is different from ours. It is in the spirit of the possible models 
approach [24], which updates models of a propositional theory separately, thus 
satisfying the update postulate U8. However, like in Inoue and Sakama’s ap- 
proach, rules are not removed on the basis of causal rejection. In particular, the 
same result is obtained on the example there. Step 2 indicates a strong update 
flavor of the approach, since rules are unnecessarily abandoned. For example, 
update of P\ = {p ^ not q} with P2 = {<? <— notp} results in P2, even though 
Pi U P2 is consistent. Since the result of an update leads to a set of programs, 
in general, naive handling of updates requires exponential space. 

7 Conclusion 

We have considered the approach to updating logic programs based on dynamic 
logic programs [2,3] and investigated various properties of this approach. Com- 
paring it to other approaches and related work, we found that it is equivalent to 
a fragment of inheritance programs in [9] . 

Several issues remain for further work. A natural issue is the inverse of addi- 
tion, i.e. retraction of rules from a logic program. Dynamic logic programming 
evolved into LUPS [3], which is a language for specifying update behavior in 
terms of addition and retraction of sets of rules to a logic program. LUPS is 
generic, however, as in principle, different approaches to updating logic programs 
could provide the semantical basis for an update step. Exploring properties of the 
general framework, as well as of particular such instantiations, would be worth- 
while. Furthermore, reasoning about update programs describing the behavior 
of agents programmed in LUPS is an interesting issue. 

Another issue are postulates for update operators on logic programs and, 
more generally, on nonmonotonic theories. As we have seen, several postulates 
from the area of logical theory change fail for dynamic logic programs (see [8] 
for related observations). This may partly be explained by nonmonotonicity of 
stable semantics and the dominant role of syntax for update embodied by causal 
rejection. However, similar features are not exceptional in the context of logic 
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programming. It would be interesting to know further postulates and desiderata 
for update of logic programs besides the ones considered here, and an AGM style 
characterization of update operators compliant with them. 
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Abstract This paper reports on the ongoing KeY project aimed at 
bridging the gap between (a) object-oriented software engineering meth- 
ods and tools and (b) deductive verification. A distinctive feature of our 
approach is the use of a commercial CASE tool enhanced with function- 
ality for formal specification and deductive verihcation. 

1 Introduction 

1.1 Analysis of the Current Situation 

While formal methods are by now well established in hardware and system design 
(the majority of producers of integrated circuits are routinely using BDD-based 
model checking packages for design and validation), usage of formal methods 
in software development is currently confined essentially to academic research 
projects. There are industrial applications of formal software development [8], 
but they are still exceptional [9]. 

The limits of applicability of formal methods in software design are not de- 
fined by the potential range and power of existing approaches. Several case stud- 
ies clearly demonstrate that computer-aided specification and verification of re- 
alistic software is feasible [18]. The real problem lies in the excessive demand 
imposed by current tools on the skills of prospective users: 

1. Tools for formal software specification and verification are not integrated 
into industrial software engineering processes. 

2. User interfaces of verification tools are not ergonomic: they are complex, 
idiosyncratic, and are often without graphical support. 

3. Users of verification tools are expected to know syntax and semantics of one 
or more complex formal languages. Typically, at least a tactical program- 
ming language and a logical language are involved. And even worse, to make 
serious use of many tools, intimate knowledge of employed logic calculi and 
proof search strategies is necessary. 
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Successful specification and verification of larger projects, therefore, is done sep- 
arately from software development by academic specialists with several years of 
training in formal methods, in many cases by the tool developers themselves. 

While this is viable for projects with high safety and low secrecy demands, 
it is unlikely that formal software specification and verification will become a 
routine task in industry under these circumstances. 

The future challenge for formal software specification and verification is to 
make the considerable potential of existing methods and tools feasible to use in 
an industrial environment. This leads to the requirements: 

1. Tools for formal software specification and verification must be integrated 
into industrial software engineering procedures. 

2. User interfaces of these tools must comply with state-of-the-art software 
engineering tools. 

3. The necessary amount of training in formal methods must be minimized. 
Moreover, techniques involving formal software specification and verification 
must be teachable in a structured manner. They should be integrated in 
courses on software engineering topics. 

To be sure, the thought that full formal software verification might be possible 
without any background in formal methods is utopian. An industrial verification 
tool should, however, allow for gradual verification so that software engineers 
at any (including low) experience level with formal methods may benefit. In 
addition, an integrated tool with well-defined interfaces facilitates “outsourcing” 
those parts of the modeling process that require special skills. 

Another important motivation to integrate design, development, and verifi- 
cation of software is provided by modern software development methodologies 
which are iterative and incremental. Post mortem verification would enforce the 
antiquated waterfall model. Even worse, in a linear model the extra effort needed 
for verification cannot be parallelized and thus compensated by greater work 
force. Therefore, delivery time increases considerably and would make formally 
verified software decisively less competitive. 

But not only must the extra time for formal software development be within 
reasonable bounds, the cost of formal specification and verification in an indus- 
trial context requires accountability: 

4. It must be possible to give realistic estimations of the cost of each step 
in formal software specification and verification depending on the type of 
software and the degree of formalization. 

This implies immediately that the mere existence of tools for formal software 
specification and verification is not sufficient, rather, formal specification and 
verification have to be fully integrated into the software development process. 

1.2 The KgX Project 

Since November 1998 the authors work on a project addressing the goals outlined 
in the previous section; we call it the KjjX project (read “key”). 
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In the principal use case of the KeY system there are actors who want to 
implement a software system that complies with given requirements and formally 
verify its correctness. The system is responsible for adding formal details to the 
analysis model, for creating conditions that ensure the correctness of refinement 
steps (called proof obligations), for finding proofs showing that these conditions 
are satisfied by the model, and for generating counter examples if they are not. 
Special features of KeY are: 

— We concentrate on object-oriented analysis and design methods (00 AD) — 
because of their key role in today’s software development practice — , and 
on Java as the target language. In particular, we use the Unified Modeling 
Language (UML) [24] for visual modeling of designs and specifications and 
the Object Constraint Language (OCL) for adding further restrictions. This 
choice is supported by the fact, that the UML (which contains OCL since 
version 1.3) is not only an OMG standard, but has been adopted by all major 
OOAD software vendors and is featured in recent OOAD textbooks [22]. 

— We use a commercial CASE tool as starting point and enhance it by ad- 
ditional functionality for formal specification and verification. The current 
tool of our choice is TogetherSoft’s Together 4.0. 

— Formal verification is based on an axiomatic semantics of the real program- 
ming language Java Card [29] (soon to be replaced by Java 2 Micro Edition, 
J2ME). 

— As a case study to evaluate the usability of our approach we develop a sce- 
nario using smart cards with Java Card as programming language [15,17]. 
Java smart cards make an extremely suitable target for a case study: 

• As an object-oriented language, Java Card is well suited for OOAD; 

• Java Card lacks some crucial complications of the full Java language 
(no threads, fewer data types, no graphical user interfaces); 

• Java Card applications are small (Java smart cards currently offer 16K 
memory for code); 

• at the same time, Java Card applications are embedded into larger 
program systems or business processes which should be modeled (though 
not necessarily formally verified) as well; 

• Java Card applications are often security-critical, thus giving incentive 
to apply formal methods; 

• the high number (usually millions) of deployed smart cards constitutes a 
new motivation for formal verification, because, in contrast to software 
run on standard computers, arbitrary updates are not feasible;^ 

— Through direct contacts with software companies we check the soundness of 
our approach for real world applications (some of the experiences from these 
contacts are reported in [3]). 

The KeY system consists of three main components (see the Figure below on 
the right): 

^ While Java Card applets on smart cards can be updated in principle, for security 
reasons this does not extend to those applets that verify and load updates. 
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~ The modeling component: this 

component is based on the CASE Kgy System 
tool and is responsible for all user 
interactions (except interactive de- 
duction) . It is used to generate and 
refine models, and to store and 
process them. The extensions for 
precise modeling contains, e.g., ed- 
itor and parser for the OCL. Ad- 
ditional functionality for the verifi- 
cation process is provided, e.g., for 
writing proof obligations. 

— The verification manager: the link between the modeling component and the 
deduction component. It generates proof obligations expressed in formal logic 
from the refinement relations in the model. It stores and processes partial 
and completed proofs; and it is responsible for correctness management (to 
make sure, e.g., that there are no cyclic dependencies in proofs). 

— The deduction component. It is used to actually construct proofs — or counter 
examples — for proof obligations generated by the verification manager. It is 
based on an interactive verification system combined with powerful auto- 
mated deduction techniques that increase the degree of automation; it also 
contains a part for automatically generating counter examples from failed 
proof attempts. The interactive and automated techniques and those for 
finding counter examples are fully integrated and operate on the same data 
structures. 

Although consisting of different components, the KeY system is going to be fully 
integrated with a uniform user interface. 

A first KeY system prototype has been implemented, integrating the CASE 
tool Together and the system IBIJa [16] as (interactive) deduction component 
(it has limited capabilities and lacks the verification manager) . Work on the full 
KeY system is in progress. 



Modeling Component 



Verification Manager 



Deduction Component 



automated 
counter examples 



2 Designing a System with KgX 

2.1 The Modeling Process 

Software development is generally divided into four activities: analysis, design, 
implementation, and test. The KeY approach embraces verification as a fifth cat- 
egory. The way in which the development activities are arranged in a sequential 
order over time is called modeling process. It consists of different phases. The 
end of each phase is defined by certain criteria the actual model should meet 
(milestones) . 

In some older process models like the waterfall model or Boehm’s spiral model 
no difference is made between the main activities — analysis, design, implemen- 
tation, test — and the process phases. More recent process models distinguish 
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between phases and activities very carefully; for example, the Rational Unified 
Process [19] uses the phases inception, elaboration, construction, and transition 
along with the above activities. 

The KeY system does neither support nor require the usage of a particular 
modeling process. However, it is taken into account that most modern processes 
have two principles in common. They are iterative and incremental. The design 
of an iteration is often regarded as the refinement of the design developed in the 
previous iteration. This has an influence on the way in which the KeY system 
treats UML models and additional verification tasks (see Section 2.3). The veri- 
fication activities are spread across all phases in software development. They are 
often carried out after test activities. 

We do not assume any dependencies be- progress in modeling 

tween the increments in the development pro- 
cess and the verification of proof obligations. 

On the right, progress in modeling is depicted 
along the horizontal axis and progress in ver- 
ifying proof obligations on the vertical axis. 

The overall goal is to proceed from the up- 
per left corner (empty model, nothing proven) 
to the bottom right one (complete model, all 
proof obligations verified). There are two ex- 
treme ways of doing that: 



(a) 



',W 



— First complete the whole modeling and coding process, only then start to 
verify (line (a)). 

— Start verifying proof obligations as soon as they are generated (line (b)). 



In practice an intermediate approach is chosen (line (c)). How this approach 
does exactly look is an important design decision of the verification process with 
strong impact on the possibilities for reuse and is the topic of future research. 



2.2 Specification with the UML and the OCL 

The diagrams of the Unified Modeling Language provide, in principle, an easy 
and concise way to formulate various aspects of a specification, however, as Steve 
Cook remarked [31, foreword]: “[ . . . ] there are many subtleties and nuances of 
meaning diagrams cannot convey by themselves.” 

This was a main source of motivation for the development of the Object 
Constraint Language (OCL), part of the UML since version 1.3 [24]. Constraints 
written in this language are understood in the context of a UML model, they 
never stand by themselves. The OCL allows to attach preconditions, postcondi- 
tions, invariants, and guards to specific elements of a UML model. 

When designing a system with KeY, one develops a UML model that is en- 
riched by OCL constraints to make it more precise. This is done using the CASE 
tool integrated into the KeY system. To assist the user, the KeY system provides 
menu and dialog driven input possibility. Certain standard tasks, for example. 
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generation of formal specifications of inductive data structures (including the 
common ones such as lists, stacks, trees) in the UML and the OCL can be done 
in a fully automated way, while the user simply supplies names of constructors 
and selectors. Even if formal specifications cannot fully be composed in such a 
schematic way, considerable parts usually can. 

In addition, we have developed a method supporting the extension of a UML 
model by OCL constraints that is based on enriched design patterns. In the 
KeY system we provide common patterns that come complete with predefined 
OCL constraint schemata. They are flexible and allow the user to generate well- 
adapted constraints for the different instances of a pattern as easily as one uses 
patterns alone. The user needs not write formal specifications from scratch, but 
only to adapt and complete them. A detailed description of this technique and 
of experiences with its application in practice is given in [4] . 

As an example, consider the 
composite pattern, depicted on 
the right [11, p. 163ff|. This is a 
ubiquitous pattern in many con- 
texts such as user interfaces, re- 
cursive data structures, and, in 
particular, in the model for the 
address book of an email client 
that is part of one of our case 
studies. 

The concrete Add and Remove operations in Composite are intuitively clear 
but leave some questions unanswered. Can we add the same element twice? Some 
implementations of the composite pattern allow this [14]. If it is not intended, 
then one has to impose a constraint, such as: 

context Composite: : Add (c : Component) 

post: self . children-^select (p I p = c)^size = 1 

This is a postcondition on the call of the operation Add in OCL syntax. After 
completion of the operation call, the stated postcondition is guaranteed to be 
true. Without going into details of the OCL, we give some hints on how to read 
this expression. The arrow indicates that the expression to its left represents 
a collection of objects (a set, a bag, or a sequence), and the operation to its right 
is to be applied to this collection. The dot is used to navigate within diagrams 
and (here) yields those objects associated to the item on its left via the role name 
on its right. If C is the multiset of all children of the object self to which Add 
is applied, then the select operator yields the set A = {p C C | p = c} and the 
subsequent integer- valued operation size gives the number of elements in A. 
Thus, the postcondition expresses that after adding c as a child to self, the 
object c occurs exactly once among the children of self. 

There are a lot of other useful (and more complex) constraints, e.g., the 
constraint that the child relationship between objects of class Component is 
acyclic. 
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2.3 The Kgy Module Concept 

The KeY system supports modularization of the model in a particular way. 
Those parts of a model that correspond to a certain component of the modeled 
system are grouped together and form a module. Modules are a different struc- 
turing concept than iterations and serve a different purpose. A module contains 
all the model components (diagrams, code etc.) that refer to a certain system 
component. A module is not restricted to a single level of refinement. 

There are three main reasons behind the module concept of the KeY system: 

Structuring: Models of large systems can be structured, which makes them 
easier to handle. 

Information hiding: Parts of a module that are not relevant for other modules 
are hidden. This makes it easier to change modules and correct them when 
errors are found, and to re-use them for different purposes. 

Verification of single modules: Different modules can be verified separately, 
which allows to structure large verification problems. If the size of modules 
is limited, the complexity of verifying a system grows linearly in the number 
of its modules and thus in the size of the system. This is indispensable for 
the scalability of the KeY approach. 

In the KeY approach, a hierarchical module concept with sub-modules sup- 
ports the structuring of large models. The modules in a system model form a 
tree with respect to the sub- module relation. 

Besides sub-modules and model components, a module contains the refine- 
ment relations between components that describe the same part of the modeled 
system in two consecutive levels of refinement. The verification problem associ- 
ated with a module is to show that these refinements are correct (see Section 3.1). 
The refinement relations must be provided by the user; typically, they include a 
signature mapping. 

To facilitate information hiding, a module is divided into a public part, its 
contract, and a private (hidden) part; the user can declare parts of each re- 
finement level as public or private. Only the public information of a module A 
is visible in another module B provided that module B implicitly or explicitly 
imports module A. Moreover, a component of module B belonging to some re- 
finement level can only see the visible information from module A that belongs 
to the same level. Thus, the private part of a module can be changed as long 
as its contract is not affected. For the description of a refinement relation (like 
a signature mapping) all elements of a module belonging to the initial model or 
the refined model are visible, whether declared public or not. 

As the modeling process proceeds through iterations, the system model be- 
comes ever more precise. The final step is a special case, though: the involved 
models — the implementation model and its realization in Java — do not neces- 
sarily differ in precision, but use different paradigms (specification vs. implemen- 
tation) and different languages (UML with OCL vs. Java).^ 

^ In conventional verification systems that do not use an iterative modeling process 
[25,27], only these final two models exist (see also the following subsection). In such 
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Below is a schematic example for the levels of refinement and the modules 
of a system model (the visibility aspect of modules is not represented here). 
Stronger refinement may require additional structure via (sub-)modules, hence 
the number of modules may increase with the degree of refinement. 




I I Part of module within one refinement Refinement relation 

I I Module Import relation 



Although the import and refinement relations are similar in some respects, 
there is a fundamental difference: by way of example, consider a system compo- 
nent being (imprecisely) modeled as a class Datastorage in an early iteration. It 
may later be refined to a class DataSet, which replaces Datastorage. On the other 
hand, the module containing DataSet could import a module Data List and use 
lists to implement sets, in which case lists are not a refinement of sets and do 
not replace them. 

Relation of KQX Modules to other Approaches The ideas of refinement and mod- 
ularization in the KeY module concept can be compared with (and are partly 
influenced by) the KIV approach [27] and the B Method [1]. 

In KIV, each module (in the above sense) corresponds to exactly two refine- 
ment levels, that is to say, a single refinement step. The first level is an algebraic 
data type, the second an imperative program, whose procedures intentionally im- 
plement the operations of the data type. The import relation allows the algebraic 
data type operations (not the program procedures!) of the imported module to 
appear textually in the program of the importing module. In contrast to this, 
the Java code of a KeY module directly calls methods of the imported module’s 
Java code. Thus, the object programs of our method are pure Java programs. 
Moreover, KeY modules in general have more than two refinement levels. 

The B Method offers (among other things) multi-level refinement of abstract 
machines. There is an elaborate theory behind the precise semantics of a re- 
finement and the resulting proof obligations. This is possible, because both, a 
machine and its refinement, are completely formal, even if the refinement hap- 
pens to be less abstract. That differs from the situation in KeY, where all but the 
last refinement levels are UML-based, and a refined part is typically more formal 
than its origin. KeY advocates the integrated usage of notational paradigms as 
opposed to, for example, prepending OOM to abstract machine specification in 
the B Method [21]. 

systems, modules consist of a specification and an implementation that is a refine- 
ment of the specification. 
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2.4 The Internal State of Objects 

The formal specification of objects and their behavior requires special techniques. 
One important aspect is that the behavior of objects depends on their state that 
is stored in their attributes, however, the methods of a Java class can in general 
not be described as functions on their input as they may have side effects and 
change the state. To fully specify the behavior of an object or class, it must be 
possible to refer to its state (including its initial state). Difficulties may arise 
if methods for observing the state are not defined or are declared private and, 
therefore, cannot be used in the public contract of a class. To model such classes, 
observer methods have to be added. These allow to observe the state of a class 
without changing it. 

Example 1. Let class Registry contain a method seen (o : Obj ect ) : Boolean 
that maintains a list of all the objects it has “seen”. It returns false, if it 
“sees” an object for the first time, and true, otherwise. In this example, we 
add the function state () :Set (Object) allowing to observe the state of an 
object of class Registry by returning the set of all seen objects. The behavior of 
seen can now be specified in the OCL as follows: 

context Registry: : seen (o : Obj ect ) 
post: result = state@pre ( ) — >includes (o) and 
state 0 = state@pre 0 ^including (o) 

The OCL key word result refers to the return value of seen, while @pre 
gives the result of state () before invocation of seen, which we denote by 
oldstate. The OCL expression state@pre () ^includes (o) then stands for 
o e oldstate and stateOpre ( ) ^including (o) stands for oldstate U {o}. 

3 Formal Verification with KgX 

Once a program is formally specified to a sufficient degree one can start to for- 
mally verify it. Neither a program nor its specification need to be complete in 
order to start verifying it. In this case one suitably weakens the postconditions 
(leaving out properties of unimplemented or unspecified parts) or strengthens 
preconditions (adding assumptions about unimplemented parts). Data encapsu- 
lation and structuredness of 00 designs are going to be of great help here. 

3.1 Proof Obligations 

We use constraints in two different ways: first, they can be part of a model (the 
default); these constraints do not generate proof obligations by themselves. Sec- 
ond, constraints can be given the status of a proof obligation; these are not part 
of the model, but must be shown to hold in it. Proof obligations may arise in- 
directly from constraints of the first kind: by checking consistency of invariants, 
pre- and postconditions of a superclass and its subclasses, by checking consis- 
tency of the postcondition of an operation and the invariant of its result type. 
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etc. Even more important are proof obligations arising from iterative refinement 
steps. To prove that a diagram D' is a sound refinement of a diagram D requires 
to check that the assertions stated in D' entail the assertions in D. A particular 
refinement step is the passage from a fully refined specification to its realization 
in concrete code. 

3.2 Dynamic Logic 

We use Dynamic Logic (DL) [20] — an extension of Hoare logic [2] — as the logical 
basis of the KeY system’s software verification component. We believe that this 
is a good choice, as deduction in DL is based on symbolic program execution and 
simple program transformations, being close to a programmer’s understanding 
of Java Card. For a more detailed description of our Java Card DL than given 
here, see [5]. 

DL is successfully used in the KIV software verification system [27] for an 
imperative programming language; and Poetzsch-Heffter and Muller’s definition 
of a Hoare logic for a Java subset [26] shows that there are no principal obstacles 
to adapting the DL/Hoare approach to 00 languages. 

DL can be seen as a modal predicate logic with a modality ip) for every 
program p (p can be any legal Java Card program); {p) refers to the successor 
worlds (called states in the DL framework) reachable by running the program p. 
In classical DL there can be several such states (worlds) because the programs 
can be non-deterministic; here, since Java Card programs are deterministic, 
there is exactly one such world (if p terminates) or there is none (if p does not 
terminate). The formula {p)(j) expresses that the program p terminates in a state 
in which (j) holds. A formula (j) (p)V’ is valid, if for every state s satisfying 

precondition (j) a run of the program p starting in s terminates, and in the 
terminating state the postcondition if) holds. 

The formula (j) (p)V’ is similar to the Hoare triple {4'}p{i^}- In contrast to 

Hoare logic, the set of formulas of DL is closed under the usual logical operators: 
In Hoare logic, the formulas (j) and if) are pure first-order formulas, whereas in 
DL they can contain programs. DL allows programs to occur in the descriptions 
(j) resp. Ip of states. With is feature it is easy, for example, to specify that a 
data structure is not cyclic (it is impossible in first-order logic). Also, all Java 
constructs (e.g., instanceof ) are available in DL for the description of states. So 
it is not necessary to define an abstract data type state and to represent states 
as terms of that type (like in [26]); instead, DL formulas can be used to give a 
(partial) description of states, which is a more flexible technique and allows to 
concentrate on the relevant properties of a state. 

In comparison to classical DL (that uses a toy programming language), a DL 
for a “real” 00 programming language like Java Card has to cope with some 
complications: (1) A program state does not only depend on the value of (local) 
program variables but also on the values of the attributes of all existing objects. 
(2) Evaluation of a Java expression may have side effects, so there is a difference 
between expressions and logical terms. (3) Such language features as built-in data 
types, exception handling, and object initialisation must be handled. 
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3.3 Syntax and Semantics of Java Card DL 

We do not allow class definitions in the programs that are part of DL formulas, 
but define syntax and semantics of DL formulas wrt a given Java Card program 
(the context), i.e., a sequence of class definitions. The programs in DL formu- 
las are executable code and comprise all legal Java Card statements, includ- 
ing: (a) expression statements (assignments, method calls, new-statements, etc.); 

(b) blocks and compound statements built with if-else, switch, for, while, 
and do-while; (c) statements with exception handling using try-catch-f inally; 
(d) statements that redirect the control flow (continue, return, break, throw). 

We allow programs in DL formulas (not in the context) to contain logical 
terms. Wherever a Java Card expression can be used, a term of the same type 
as the expression can be used as well. Accordingly, expressions can contain terms 
(but not vice versa). Formulas are built as usual from the (logical) terms, the 
predicate symbols (including the equality predicate =), the logical connectives 

A, V, the quantifiers V and 3 (that can be applied to logical variables but 
not to program variables), and the modal operator (p), i.e., if p is a program 
and (() is a formula, then {p)(j) is a formula as well. 

The models of DL consist of program states. These states share the same 
universe containing a sufficient number of elements of each type. In each state a 
(possibly different) value (an element of the universe) of the appropriate type is 
assigned to: (a) the program variables, (b) the attributes (fields) of all objects, 

(c) the class attributes (static fields) of all classes in the context, and (d) the 
special object variable this. Variables and attributes of object types can be 
assigned the special value null. States do not contain any information on control 
flow such as a program counter or the fact that an exception has been thrown. 

The semantics of a program p is a state transition, i.e., it assigns to each 
state s the set of all states that can be reached by running p starting in s. 
Since Java Card is deterministic, that set either contains exactly one state or 
is empty. The set of states of a model must be closed under the reachability 
relation for all programs p, i.e., all states that are reachable must exist in a 
model (other models are not considered). 

We consider programs that terminate abnormally to be non-terminating: 
nothing can be said about their final state. Examples are a program that throws 
an uncaught exception and a return statement outside of a method invocation. 
Thus, for example, (throw x-)(j> is unsatisfiable for all 



3.4 A Sequent Calculus for Java Card DL 

We outline the ideas behind our sequent calculus for Java Card DL and give 
some of its basic rules (actually, simplified versions of the rules, e.g., initialisation 
of objects and classes is not considered). The DL rules of our calculus operate on 

® It is still possible to express and (if true) prove the fact that a program p ter- 
minates abnormally. For example, (tryfp }catch{Exception e})(^e = null) ex- 
presses that p throws an exception. 
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r h end = true _T h (tt prg while (end) prg 
_T h {tt while ( end ) u))(j) 

r h end = false F h {Tvuj)(j) 
r \- (tt vhile (end) prg u))(j> 

r h instanceof {exc , T) F \- {tv trjie = exc; gjf inallyfr} Lo}(j> 
F \- (tv tryfthrow exc; p}-catch(r e){5}finally-[T’}- o>)(^ 

F h -< instanceof {exc , T) F \- (tv r; throw exc; to)(j> 

_r h (tt tryfthrow ea:c ; p}-catch(r e )-[g }f inallyfr }■ (jj)cj> 

F \- {tt r to)(j) 

_r h (tt try{}catch(r e ) {5 }f inallyfr }■ u>)ij> 



( 1 ) 

(2) 

( 3 ) 

( 4 ) 

( 5 ) 



Table 1. Some of the rules of our calculus for Java Card DL. 



the first active command p of a program irpu). The non-active prefix tt consists 
of an arbitrary sequence of opening braces labels, beginnings “try[” of 
try-catch blocks, etc. The prefix is needed to keep track of the blocks that the 
(first) active command is part of, such that the commands throw, return, break, 
and continue that abruptly change the control flow are handled correctly. (In 
classical DL, where no prefixes are needed, any formula of the form (p q)<j) can 
be replaced by {p){q)4>- In our calculus, splitting of {TTpqco)(j) into {'Kp){qu!)(j) is 
not possible (unless the prefix tt is empty) because irp is not a valid program; 
and the formula {'npijj){T:qui)4> cannot be used either because its semantics is in 
general different from that of {'Kpquj)(j).) 

As examples, we present the rules for while loops and for exception handling. 
The rules operate on sequents F \- <j). The semantics of a sequent is that the 
conjunction of the DL formulas in F implies the DL formula (f). Sequents are 
used to represent proof obligations, proof (sub-)goals, and lemmata. 

Rules (1) and (2) in Table 1 allow to “unwind” while loops. They are sim- 
plified versions that only work if (a) the condition end is a logical term (i.e., 
has side effects), and (b) the program prg does not contain a continue state- 
ment. These rules allow to handle loops if used in combination with induction 
schemata. Similar rules are defined for do-while and for loops. 

Rules (3)-(5) handle try-catch-f inally blocks and the throw statement. 
Again, these are simplified versions of the actual rules; they are only applicable 
if (a) exc is a logical term (e.g., a program variable), and (b) the statements 
break, continue, return do not occur. Rule (3) applies, if an exception exc 
is thrown that is an instance of exception class r, i.e., the exception is caught; 
otherwise, if the exception is not caught, rule (4) applies. Rule (5) applies if the 
try block is empty and terminates normally. 

3.5 The KgX Deduction Component 

The KeY system comprises a deductive component, that can handle KeY-DL. 
This KeY prover combines interactive and automated theorem proving tech- 
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niques. Experience with the KIV system [27] has shown how to cope with DL 
proof obligations. The original goal is reduced to first-order predicate logic using 
such DL rules as shown in the previous subsections. First-order goals can be 
proven using theory specific knowledge about the used data types. 

We developed a language for expressing knowledge of specific theories — we 
are thinking here mainly of theories of abstract data types — in the form of proof 
rules. We believe that this format, stressing the operational aspect, is easier 
to understand and simpler to use than alternative approaches coding the same 
knowledge in declarative axioms, higher-order logic, or fixed sets of special proof 
rules. This format, called schematic theory specific rules, is explained in de- 
tail in [16] and has been implemented in the interactive proof system IBIJa 
(illwww.ira.uka.de/~ibija). In particular, a schematic theory specific rule 
contains: (a) Pure logical knowledge, (b) information on how this knowledge is 
to be used, and (c) information on when and where this knowledge should be 
presented for interactive use. 

Nearly all potential rule applications are triggered by the occurrence of cer- 
tain terms or formulas in the proof context. The easy-to-use graphical user in- 
terface of IBIJa supports invocation of rule applications by mouse clicks on the 
relevant terms and formulas. The rule schema language is expressive enough to 
describe even complex induction rules. The rule schema language is carefully 
designed in such a way that for every new schematic theory specific rule, IBIJa 
automatically generates proof obligations in first-order logic. Once these obli- 
gations are shown to be true the soundness of all applications of this rule is 
guaranteed. Hence, during each state of a proof, soundness-preserving new rules 
can be introduced. 

To be practically useful, interactive proving must be enhanced by automat- 
ing intermediate proof steps as much as possible. Therefore, the KeY prover 
combines IBIJa with automated proof search in the style of analytic tableaux. 
This integration is based on the concepts described in [12,13]. A screen shot of 
a typical situation as it may arise during proof construction with our prototype 
is shown below. The user may either interactively apply a rule (button “Apply 
Selected Rule”) or invoke the automated deduction component (button “Start 
PRINS”). 
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In a real development process, resulting programs often are bug-ridden, there- 
fore, the ability of disproving correctness is as important as the ability of proving 
it. The interesting and common case is that neither correctness nor its negation 
are deducible from given assumptions. A typical reason is that data structures 
are underspecified. We may, for example, not have any knowledge about the be- 
havior of, say, pop(s: Stack) : Stack if s is empty. To recognize such situations, 
which often lead to bugs in the implementation, we develop special deductive 
techniques. They are based on automatically constructing interpretations (of 
data type operations) that fulfill all assumptions but falsify the hypothesis. 

4 Related Work 

There are many projects dealing with formal methods in software engineering 
including several ones aimed at Java as a target language. There is also work 
on security of Java Card and ActiveX applications as well as on secure smart 
card applications in general. We are, however, not aware of any project quite 
like ours. We mention some of the more closely related projects. 

A thorough mathematical analysis of Java using Abstract State Machines 
has been given in [6]. Following another approach, a precise semantics of a Java 
sublanguage was obtained by embedding it into Isabelle/HOL [23]; there, an 
axiomatic semantics is used in a similar spirit as in the present paper. 

The COGITO project [30] resulted in an integrated formal software develop- 
ment methodology and support system based on extended Z as specification 
language and Ada as target language. It is not integrated into a CASE tool, but 
stand-alone. 

The FuZE project [10] realized CASE tool support for integrating the Fu- 
sion OOAD process with the formal specification language Z. The aim was 
to formalize OOAD methods and notations such as the UML, whereas we are 
interested to derive formal specifications with the help of an OOAD process 
extension. 

The goal of the Quest project [28] is to enrich the CASE tool AutoFo- 
CUS for description of distributed systems with means for formal specification 
and support by model checking. Applications are embedded systems, description 
formalisms are state charts, activity diagrams, and temporal logic. 

Aim of the SysLab project is the development of a scientifically founded ap- 
proach for software and systems development. At the core is a precise and formal 
notion of hierarchical “documents” consisting of informal text, message sequence 
charts, state transition systems, object models, specifications, and programs. All 
documents have a “mathematical system model” that allows to precisely describe 
dependencies or transformations [7]. 

The goal of the PROSPER project was to provide the means to deliver the 
benefits of mechanized formal specification and verification to system designers 
in industry (www.dcs.gla.ac.uk/prosper/index.html). The difference to the 
KeY project is that the dominant goal is hardware verification; and the software 
part involves only specification. 
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5 Conclusion and the Future of KgX 

In this paper we described the current state of the KeY project and its ultimate 
goal: To facilitate and promote the use of formal verification in an industrial 
context for real-world applications. It remains to be seen to which degree this 
goal can be achieved. 

Our vision is to make the logical formalisms transparent for the user with re- 
spect to 00 modeling. That is, whenever user interaction is required, the current 
state of the verification task is presented in terms of the environment the user 
has created so far and not in terms of the underlying deduction machinery. The 
situation is comparable to a symbolic debugger that lets the user step through 
the source code of a program while it actually executes compiled machine code. 
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Abstract We introduce a family of languages intended for represent- 
ing knowledge and reasoning about metric (and more general distance) 
spaces. While the simplest language can speak only about distances be- 
tween individual objects and Boolean relations between sets, the more 
expressive ones are capable of capturing notions such as ‘somewhere in 
(or somewhere out of) the sphere of a certain radius’, ‘everywhere in 
a certain ring’, etc. The computational complexity of the satisfiability 
problem for formulas in our languages ranges from NP-completeness to 
undecidability and depends on the class of distance spaces in which they 
are interpreted. Besides the class of all metric spaces, we consider, for 
example, the spaces R x R and N x N with their natural metrics. 



1 Introduction 

The concept of ‘distance between objects’ is one of the most fundamental abstrac- 
tions both in science and in everyday life. Imagine for instance (only imagine) 
that you are going to buy a house in London. You then inform your estate agent 
about your intention and provide her with a number of constraints: 

(A) The house should not be too far from your college, say, not more than 
10 miles. 

(B) The house should be close to shops, restaurants, and a movie theatre; 
all this should be reachable, say, within 1 mile. 

(C) There should be a ‘green zone’ around the house, at least within 2 miles 
in each direction. 

(D) Factories and motorways must be far from the house, not closer than 
5 miles. 

(E) There must be a sports center around, and moreover, all sports centers 
of the district should be reachable on foot, i.e., they should be within, 
say, 3 miles. 

(F) And of course there must be a tube station around, not too close, but 
not too far either — somewhere between 0.5 and 1 mile. 

M. Ojeda-Aciego et al. (Eds.): JELIA2000, LNAI 1919, pp. 37—56, 2000. 

@ Springer- Verlag Berlin Heidelberg 2000 
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‘Distances’ can be induced by different measures. We may be interested in the 
physical distance between two cities a and 6, i.e., in the length of the straight 
(or geodesic) line between a and b. More pragmatic would be to bother about 
the length of the railroad connecting a and b, or even better the time it takes to 
go from a to 6 by train (plane, ship, etc.). But we can also define the distance 
as the number of cities (stations, friends to visit, etc.) on the way from a to b, 
as the difference in altitude between a and b, and so forth. 

The standard mathematical models capturing common features of various 
notions of distance are known as metric spaces (see e.g. [4]). We define a metric 
space as a pair D = {W,d), where W is a set (of points) and d a function from 
W X W into K, the metric on W, satisfying the following conditions, for all 
x,y, z G W: 

d{x,y) = 0 iS X = y, (1) 

d{x,z) < d{x,y) + d{y,z), (2) 

d{x,y) = d{y,x). (3) 

The value d{x,y) is called the distance from the point x to the point y} 

It is to be noted, however, that although quite acceptable in many cases, the 
defined concept of metric space is not universally applicable to all interesting 
measures of distances between points, especially those used in everyday life. 
Here are some examples: 

(i) Suppose that W consists of the villages in a certain district and d(x, y) 
denotes the time it takes to go from a; to y by train. Then the function d is not 
necessarily total, since there may be villages without stations. 

(ii) If d{x, y) is the flight-time from x to y then, as we know it too well, d is 
not necessarily symmetric, even approximately (just go from Malaga to Tokyo 
and back). 

(iii) Often we do not measure distances by means of real numbers but rather 
using more fuzzy notions such as ‘short’, ‘medium’, ‘long’. To represent these 
measures we can, of course, take functions d from WxW into the set {1, 2, 3} C K 
and define short := 1, medium := 2, and long := 3. So we can still regard 
these distances as real numbers. However, for measures of this type the triangle 
inequality (2) does not make sense (short plus short can still be short, but it can 
be also medium or long). 

In this paper we assume first that distance functions are total and satisfy 
(l)-(3), i.e., we deal with standard metric spaces. But then, in Section 6, we 
discuss how far our results can be extended if we consider more general distance 
spaces. 

Our main aim in the paper is to 

design formal languages of metric (or more general distance) spaces that 

can be used to represent and reason about (a substantial part of) our 

^ Usually axioms (2) and (3) are combined into one axiom d{y, z) < d{x, y) + d{x, z) 
which implies the symmetry property (3); cf. [4]. In our case symmetry does not 
follow from the triangle inequality (2). We will use this fact in Section 6. 
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everyday knowledge of distances, and that are at the same time as com- 
putationally tractable as possible. 

The next step will be to integrate the developed languages with formalisms 
intended for qualitative spatial reasoning (e.g. RCC-8), temporal reasoning, and 
maybe even combined spatio-temporal reasoning (e.g. [19]). 

The requirement of computational effectiveness imposes rather severe limita- 
tions on possible languages of metric spaces. For instance, we can hardly use the 
full power of the common mathematical formalism which allows arithmetic oper- 
ations and quantification over distances as in the usual definition of a continuous 
function / from D to K: 

Vx e VF Ve > 0 3i5 > 0 Vy G IF (d{x, y) < e ^ \f(x) — /(y)| < <5) . 

On the other hand, in everyday life a great deal of assertions about distances 
can be (and are) made without such operations and quantification. Although 
we operate quantitative information about distances, as in examples (A)-(F) 
above, the reasoning is quite often rather qualitative, with numerical data being 
involved only in comparisons (‘everywhere within 7 m distance’, ‘in more than 3 
hours’, etc.), which as we observed above can also encode such vague concepts as 
‘short’, ‘medium’, ‘long’. As travelling scientists, we don’t care about the precise 
location of Malaga, being content with the (qualitative) information that it is in 
Spain, Spain is disconnected from Germany and the U.K., and the flight-time 
to any place in Spain from Germany or the U.K. is certainly less than 4 hours. 
That is why we call our formalisms semi- qualitative, following a suggestion of 
A. Gohn. 

In the next section we propose a hierarchy of ‘semi-qualitative’ propositional 
languages intended for reasoning about distances. We illustrate their expressive 
power and formulate the results on the finite model property, decidability, and 
computational complexity we have managed to obtain so far. (The closest ‘rela- 
tives’ of our logics in the literature are the logics of place from [14,18,15,11,12] 
and metric temporal logics from [13]; see also [5].) Sections 3-5 show how some 
of these results can be proved. And in Section 6 we discuss briefly more general 
notions of ‘distance spaces.’ 

The paper is a preliminary report on our ongoing research; that is why it 
contains more questions than answers (some of them will certainly be solved by 
the time of publication) . 

2 The Logics of Metric Spaces 

All the logics of metric spaces to be introduced in this section are based on the 
following Boolean logic of space BS. The alphabet of BS contains 

— an infinite list of set (or region) variables Xi,X 2 , . . . ; 

— an infinite list of location variables xi,X 2 , ■ ■ ■; 

— the Boolean operators A and 
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Boolean combinations of set variables are called set (or region) terms. Atomic 
formulas in BS are of two types: 

— a;Et, where a; is a location variable and t a set term, 

— ti = t2, where ti and t2 are set terms. 

The intended meaning of these formulas should be clear from their syntax: xE.t 
means that x belongs to t, and ti = t2 says that t\ and t2 have the same 
extensions. 

BS-formulas are just arbitrary Boolean combinations of atoms. 

The language BS, as well as all other languages to be introduced below, is 
interpreted in metric spaces D = {W, d) by means of assignments o associating 
with every set variable X a subset a{X) of W and with every location variable 
X an element a(a;) of W. The value of a set term t in the model = (S, o) 
is defined inductively: 



Xf = a{Xi), Xi a set variable, 

(tiAt2)“ = t?nt^, 

(^t)“ = w-e. 

(If the space T) is not clear from the context, we write t^ instead of t“.) 
The truth-relation for ,85-formulas reflects the intended meaning: 



iXtl\=x^t iff o(a;) e t“, 
m[=ti = t2 iff t? = t^, 

plus the standard clauses for the Booleans. 

We write T instead of ~^{X A 0 instead of X A ~^X, and ti E t2 instead 
of ^(ti A ^^2) = T. It should be clear that TI \= t\ Q t2 iS t° C t^- 

BS can only talk about relations between sets, about their members, but not 
about distances. For instance, we can construct the following knowledge base in 
BS: 



Leipzig ^Germany , Malaga^Spain, 

Germany E Europe, Spain E Europe, 

Spain A Germany = 0. 

The metric d in S) is irrelevant for BS. ‘Real’ metric logics are defined by 
extending BS with a number of set term and formula constructs which involve 
distances. We deflne flve such logics and call them MSq, . . . , MS4. 

AASq. To begin with, let us introduce constructs which allow us to speak about 
distances between locations. Denote by MSq the language extending BS with 
the possibility of constructing atomic formulas of the form 



S{x,y) = a, 
S{x,y) < a. 
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- ^{x,y) = S{x',y'), 

- S{x,y) < 6{x',y'), 

where x, y, x' , y' are location variables and a S K-|_ (i.e., o is a non-negative real 
number). The truth-conditions for such formulas are obvious: 

\= S{x,y) = a iff d{a{x),a{y)) = a, 

^ y) < a iff d{a{x),a{y)) < a, 

^(x,y) = S{x\y') iff d(a(a;), o(y)) = d(o(a:'), a(y')). 

^{x,y) < S{x',y') iff d{a{x),a{y)) < d{a{x'),a{y')). 

MSo provides us with some primitive means for basic reasoning about regions 
and distances between locations. For example, constraint (A) from Section 1 can 
be represented as 

{S {house, college) < 10) V {S{house, college) = 10). (4) 

The main reasoning problem we are interested in is satisfiability of finite sets 
of formulas in arbitrary metric spaces or in some special classes of metric spaces, 
say, finite ones, the Euclidean n-dimensional space with the standard 

metric 

n 

dn{x,y) = , - ?/i)2, 

\ i=l 

the subspace of (with the induced metric), etc. The choice of 

metric spaces depends on applications. For instance, if we deal with time con- 
straints then the intended space can be one-dimensional (IR, di) or its subspaces 
based on Q or N. If we consider a railway system, then the metric space is finite. 

It is to be noted from the very beginning that the language AiSg as well as 
other languages MSi are uncountable because all of them contain uncountably 
many formulas of the form 8{x, y) = a, for a G IR-|- . So in general it does not make 
sense to ask whether the satisfiability problem for such languages is decidable. 

To make the satisfiability problem sensible we have to restrict the languages 
MSi to at least recursive (under some coding) subsets of K-|_ . Natural examples 
of such subsets are the non-negative rational numbers Q+ or the natural numbers 
N. 

Given a set § C IR_|_ , we denote by Ad5i[S] the fragment of MSi consisting 
of only those A45i-formulas all real numbers in which belong to §. 

For the logic MSq we have the following: 

Theorem 1. (i) The satisfiability problem for MS formulas in arbitrary 
metric spaces is decidable. 

(ii) Every finite satisfiable set of MS q- formulas is satisfiable in a finite metric 
space, or in other words, MSq has the finite model property. 

This theorem follows immediately from the proof of the finite model property 
of MS 2 in Section 5. We don’t know whether satisfiability of A45o[Q] -formulas 
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in K” is decidable. We conjecture that it is and that the complexity of the 
satisfiability problem for both arbitrary metric spaces and K" is in NP. 

In MSo we can talk about distances between points in metric spaces. Now 
we extend the language by providing constructs capable of saying that a point 
is within a certain distance from a set, which is required to represent constraint 
(B) from Section 1. 

Ad«Si. Denote by MS\ the language that is obtained by extending MSq with 
the following set term constructs: 

— if t is a set term and a G K+ , then 3<at and V<at are set terms as well. 

The semantical meaning of the new set terms is defined by 

(3<at)“ = {x & W -.3y & W {d{x, y) <aAy € f“)}, 

(V<at)“ = {x GW -.Vy GW {d{x,y) <a^yG t“)}. 

Thus xE.3<at means that ‘somewhere in or on the sphere with center x and 
radius a there is a point from t’; xE. V<at says that ‘the whole sphere with 
center x and radius a, including its surface, belongs to t.’ 

Constraints (B)-(D) are now expressible by the formulas: 

houseE3<ishops A 3<irestaurants A 3<icinemas, 
houseE V <2 green-Zone, 
houseE~'3<^{f actories V motorways). 

Here is what we know about this language: 

Theorem 2. (i) The satisfiability problem for AiS formulas in arbitrary 
metric spaces is decidable. 

(ii) AASi has the finite model property. 

(iii) The satisfiability problem for A4Si[{l}]-formulas in , d'fi) is undecid- 
able. 

Claims (i) and (ii) follow from the proof of the finite model property in 
Section 5. The proof of (iii) is omitted. It can be conducted similarly to the un- 
decidability proof in Section 3. Note that at the moment we don’t know whether 
the satisfiability in is decidable and what is the complexity of satisfiability 
of AI5i[Q]-formulas. 

A 4 .S 2 . In the same manner we can enrich the language A4Si with the constructs 
for expressing ‘somewhere outside the sphere with center x and radius a’ and 
‘everywhere outside the sphere with center x and radius o’. To this end we add 
to AIiSi two term- formation constructs: 

— if t is a set term and a G IR+, then and V>at are set terms. 



( 5 ) 

( 6 ) 
( 7 ) 
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The resulting language is denoted by M.S 2 - The intended semantical meaning 
of the new constructs is as follows: 

(3>at)“ = {a; G IT : G IT y) > aAy € t“)}, 

(V>at)“ = {x G IT : Vy G IT {d{x,y) > a^y e t“)}. 

Constraint (E) can be represented now as the formula 

house E3<3district-sports-center A V> 3 ^ district-sports.center. (8) 

The language MS 2 is quite expressive. First, it contains an analogue of the 
difference operator from modal logic (see [6]), because using V>o we can say 
‘everywhere but here’: 

\= xEV>ot iff 1= yEt for all y ^ x. 

We also have the universal modalities of [9]: the operators V and 3 can be defined 
by taking 



Vt = t A V>ot, i.e., Vt is 0 if t yf T and T otherwise, 

3t = tv 3>ot, i.e., Vt is T if f 0 and 0 otherwise. 

Second, we can simulate the nominals of [1]. Denote by MS '2 the language that 
results from M.S 2 by allowing set terms of the form {a;}, for every location 
variable x, with the obvious interpretation: 

- a({a^}) = {a(a:)}- 

In MS '2 we can say, for example, that 

{3<iwo{Leipzig} A 3<noo{Af alaya}) E France, 

i.e., ‘if you are not more than 1100 km away from Leipzig and not more than 
1100 km away from Malaga, then you are in France’. 

As far as the satisfiability problem is concerned, MS '2 is not more expressive 
than MS2- To see this, consider a finite set of AdiS^-formulas T and suppose 
that xi,...,Xn are all location variables which occur in F as set terms {xi}. 
Take fresh set variables Xi, . . . , Xn and let F' be the result of replacing all {xi] 
in F with Xi. It is readily checked that F is satisfiable in a model based on a 
metric space D iff the set of A452-formulas 

F' U {{Xi A ^3>oATi) yf 0 : i < n} 



is satisfiable in D. 

It is worth noting that, as will become obvious in the next section, the relation 
between the operators V<a and V>a corresponds to the relation between modal 
operators □ and □“ interpreted in Kripke frames by an accessibility relation R 
and its complement R, respectively; see [8] for a study of modal logics with such 
boxes. 
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Theorem 3. (i) The satisfiability problem for AiS 2 [^- formulas in arbitrary 
metric spaces is decidable. 

(ii) M.S 2 has the finite model property. 

This result will be proved in Section 5. We don’t know, however, what is the 
complexity of the satisfiability problem from (i). 

M.S 3 . To be able to express the last constraint (F) from Section 1, we need 
two more constructs: 

~ if t is a set term and a <b, then 3ff^t and Vff^t are set terms. 

The extended language will be denoted by At 53 . The truth-conditions for these 
operators are as follows: 

(3<bf)“ = {x eW :3y eW (a < d{x, y) <bAy G t“)}, 

= {x eW :\/y eW (a < d(x, y) < b ^ y G t“)}. 

In other words, iff ‘somewhere in the ring with center x, the inner radius 

a and the outer radius b, including the outer circle, there is a point from t\ 
Constraint (F) is represented then by the formula: 

houseG.3f^'^ tube-station. (9) 

(By the way, the end of the imaginary story about buying a house in London 
was not satisfactory. Having checked her knowledge base, the estate agent said: 
“Unfortunately, your constraints (4)-(9) are not satisfiable in London, where we 
have 

tube-station E 3 <3,5{factory V motorway) . 

In view of the triangle inequality, this contradicts constraints (7) and (9).”) 
Unfortunately, the language MS 3 is too expressive for many important 
classes of metric spaces. 

Theorem 4. Let 1C be a class of metric spaces containing . Then the satisfi- 
ability problem for AI53[{0, . . . , 100}]-formulas in K. is undecidable. 

This result will be proved in the next section (even for a small fragment of 
MS3). 

MS 4 . The most expressive language MS 4 we have in mind is an extension of 
MS 3 with the operators V<at, 3>at, y>at, 

Here is what we know about these operators: the satisfiability problem for 
the full language in the class of all metric spaces is of course undecidable — it 
contains MS 3 . Moreover, the operators alone determine an undecidable 
language for the class of arbitrary metric spaces (this can be proved similarly 
to the undecidability proof in Section 3). Also, a similar proof shows that the 
language with the operators V<a only is undecidable both in (W^,d 2 ) and in 
Still, various questions are open, however: for example, whether the 
language with the operators V<a only is decidable in arbitrary metric spaces or 
whether there are interesting classes of metric spaces in which MS 4 is decidable. 
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3 Undecidability 

In this section we prove a rather general undecidability result. In particular, 
Theorem 4 is its immediate consequence. 

Theorem 5. Let 1C he a class of metric spaces containing . Then the sat- 
isfiability problem for AI53[{0, 9, 10, 20, 80}] -/ormttZas (even for those with the 
operators and 3<a only) in JC is undecidahle. 

Proof. To prove this result, we reduce the undecidable N x N-tiling problem (see 
[17,2] and references therein) to the satisfiability problem in 1C. We remind the 
reader that the tiling problem for N x N is formulated as follows: given a finite set 
T = {Ti, . . . ,T;| of tiles (i.e., squares Ti with colors left{Ti), right(Ti), up{Ti), 
and down{Ti) on their edges), determine whether tiles in T can cover the grid 
N X N in such a way that the colors of adjacent edges on adjacent tiles match, 
or more precisely, whether there exists a function r : N x N ^ T such that for 
all n, TO e N: 

(a) right{T{n, to)) = left{T{n 1, to)), 

(b) up{T{n,m)) = down{T{n,m T)). 

So, suppose a set of tiles T = {Ti, . . . ,T;} is given. Our aim is to construct a 
finite set of A453[{0, 9, 10, 20, 80}]-formulas which is satisfiable in /C iff T can 
tile N X N. 

Take set variables Zi, . . . , Z/, Xq, . . . , X 4 , Yq,. . . ,¥ 4 . Let Xij = V<9(Xi A Yj), 
for i,j < 4, and let P be the set of the following formulas, where i,j <4 and 
k<l: 



Xi A Yj E 3<9Xij, Xij E < 80 ^Xij J 


Xij E -^Xinn ((aj) (m,n)), 


(10) 


Xij E V<9Z/„, 


, E -nZn {n yf to), 


(11) 


k<l 






Xij A Zfe E 3<2o(x*-H5ii A 


V 


(12) 




right(Tk)=left(Tm) 




Xij A Zfe E 3<2o(Xij>5i A 


V 


(13) 




up(Tk) = down{Tra) 





where -I-5 denotes addition modulo 5. 

The first formula in (10) is satisfied in a model = (IT, d, 0 ) iff a(W AYj) is 
the union of a set of spheres of radius 9. The second one is satisfied in iff the 
distance between any two distinct centers of spheres, all points in which belong 
to a{Xi A Yj), is more than 80. 

We are going to show that the set {xEyoo} U T is satisfiable in /C iff T can 
tile N X N. 

Lemma 1. If T can tile N x N, then {xExoo} U T is satisfiable in . 
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Proof. Suppose r:NxN^Tisa tiling. For r G put 
S'(r) = {y e : d 2 {r,y) < 9}. 

Define an assignment a into by taking, for i,j < 4 and k < 1: 

- a{Xi) = 1J{S'(50to+ 10t,20n) : m,n G N}, 

~ a(y^-) = U{5'(20n,50m+ lOj) : m,n G N}, 

~ a(Zfe) = lJ{S'(n,TO) : T{n,rn) = Tfc}. 

It is not difficult to see that (K^, o) satisfies {a;Exoo} U P. 

Lemma 2. Suppose a model = (IF, d, o) satisfies {xExoo} U P. Then there 
exists a function / : N x N ^ IF such that, for all z, j < 4 and k\,k 2 G N, 

- /(5fci + f,5fe + j) G x“-, 

- d{f{ki,k2), f{ki + 1, fej) < 20, 

- d{f {ki,k2), f {ki,k2 + 1)) < 20. 

The map t : N x N ^ T defined by taking t(ji, m) = Tk iff f{n, m) G Zf., for all 
k < I and all n, m G N, is a tiling. 

Proof. We define / inductively. Put /(0,0) = o(a:). By (12), we find a sequence 
G IF, n G N, such that 

- rco = /(0,0), 

- W 5 k+i € x“q, for alH < 4 and k GN, 

- d{Wn,Wn+l) < 20 . 

We put /(n, 0) = Wn for all n G N. Similarly, by (13) we find a sequence 
n G N, such that 

- vo = f{0,0), 

- V 5 k+j e xlp for all j < 4 and /c G N, 

- d{Vn, Vn+i) < 20 . 

Put /(0,m) = Vm for all m G N. Suppose now that / satisfies the conditions 
listed in the formulation of the lemma (on its defined domain), that it has been 
defined for all {m! , n') with m! + n' <m + n, but not for (to, n). Without loss of 
generality we can assume that n = bk\, to = 5^2 + 1> for some k\,k 2 G N. Then 
f{n,m — 1) G Xooi and so f{n,m — 1) G (3<2oXoi)“- So we can find a w' G IF 
with d{f{n,m — 1), w') < 20 such that w' G Xoi- We then put f{n,m) = w' . It 
remains to prove that / still has the required properties. To this end it suffices 
to show that d{f{n — l,m),w') < 20. We have f{n — 1,to) G X 4 d and so there 
exists a w” such that w” G Xoi and d{f{n — < 20. So it is enough to 

show that w' = w" . Suppose otherwise. Then 

- d{w" , f{n — I, to)) < 20, 

- d{f{n - 1), to), f{n - 1, TO - 1)) < 20, 

- d{f {n - 1, TO - 1), /(n, TO - 1)) < 20, 

- d(f(n, m — 1), w') < 20. 

By the triangle inequality, we then have d(w" ,w') < 80, contrary to the second 
formula in (10). 

The reader can readily check that t is a tiling. 
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4 Relational Semantics 

To prove the finite model property of M.S 2 , we require a relational representation 
of metric space models defined in Section 2. Let M C K_|_ . 

A relational metric M -model is a quadruple of the form 

& = (W, {Ra)aGM , {Ra)aGM ■, Cl) , 

where TT is a non-empty set, {Ra)aeM and {Ra)aeM are families of binary re- 
lations on W, and a is an assignment in W. The value t® of a set term t in © 
is defined inductively. The basis of induction and the case of Booleans are the 
same as in metric space models. And for set terms of the form V<at and V>at 
we put 

— (V<at)® = {w G VL : Vu G IT {wRaV 

— i'^>at)'^ = {w G IT : Vu G IT {wRaV 

The values of 3<at and 3>at are defined 
Say that the model © is M-standard 
for all a,b G M and w,u,v G W: 

(i) RaURa = W xW, 

(ii) RaC\Ra=^, 

(iii) if uRaV and a < b, then uRbV, 

(iv) if and a > b, then uRp], 

(v) uRov iff M = u, 

(vi) if uRaV and vRtw, then uRa+bW whenever a -I- 6 G M, 

(vii) uRaV iff vRaU. 

Note that as a consequence of (i), (ii) and (vi) we have: 

(viii) if uRaV and uR-^jzfj;w then vRpv. 

With every metric space model = (IT, d, a) we can associate the relational 
metric M-model 

©(9Jl) = (TT, {Ra)aGM 1 {Ra)aeM , Cl) , 
in which the relations Ra and Ra are defined as follows: 

G W {wRaV ^ d{w,v) < a), 

\/w,v G W {wRaV ^ d{w,v) > a). 

It is easy to see that ©(9Jl) is M-standard. Note that (v), (vi) and (vii) refiect 
axioms (l)-(3) of metric spaces. 

The model ©(9Jl) can be regarded as a relational representation of For 
we clearly have the following: 

Lemma 3. For every metric space model and every set term t G M.S 2 [M], 
the value oft in Wl coincides with the value oft in ©(9Jl). 



^uGt®)}, 

^ u G t®)}. 

dually. 

if the following conditions are satisfied 
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5 The Finite Model Property of A4S2 

In this section we prove that JHS 2 has the finite model property. The idea of 
the proof is as follows. 

Let (p be an A 452 -formula and let ^ for some metric space model 

= (IF, d, a). Depending on we transform into a set <P, containing only 
formulas of the form xEt, s = t, s ^ t, and S{x,y) = a, in such a way that tp 
is satisfiable in a finite model whenever <P is finitely satisfiable. Starting from 

we compute a finite set M[<1>] of real numbers containing, in particular, all 
the numbers occurring in <P. Then we replace the metric d by a new metric d' 
with (finite) range M[<P], The new model still satisfies <P. The next step is to 
filtrate (as in modal logic; see e.g. [3]) the relational metric model & — S(9Jli) 
through some suitable set of terms cl{<P). To define cl{<P), we first transform <P 
into a set which, roughly speaking, is obtained from <P by replacing every 
formula of the form S(y,z) = a with two formulas zE.X^ and yE.3<aX^ , where 
the are fresh set variables. cl{'P) will be the closure of the terms in <P' under 
syntactical rules that are similar to the rules of the Fischer-Ladner closure for 
PDL-formulas (cf. [10]). (Note, however, that in contrast to the Fischer-Ladner 
closure the closure considered here results in an exponential blow up.) 

As a result of the filtration we get a finite relational metric model . But 
unlike &, in general is not M [<?]-standard, which means that we cannot 
directly transform it into a finite metric space model. However, ©^ still has all 
the properties of M[<?]-standard models save (ii): there may exist v G such 
that wRaV and wRaV, for some w G , and a G M[<1>]. To ‘cure’ these defects, 
we make copies of such ‘bad’ points v and modify the relations Ra and Ra in ©^ 
obtaining a finite standard relational metric model ©*. (The ‘copying-method’ 
was developed by the Bulgarian school of modal logic; see [7,16]. Our technique 
follows [8]). The final step is to transform ©* into a metric space model 9Jl*. 

Let us now turn to details. Denote by term{<p) the set of all set terms oc- 
curring in (p; subipp) stands for the set of all subformulas of (p. Define a set 
^ U U ^3 by taking: 

= {xEt : (xEt) G sub{(p), ^ xEt} U 
{xE^t : (xEt) G sub{ip), ^ x^t}, 

<1>2 = {s = t : {s = t) G sub{ip), ]= s = t} U 

{s yf t : (s = t) G sub{(p), ]= s yf t}, 

^3 = {S{y, z) = a : S{y,z) G term{<p), a = d{a{y), a(z))}. 

It should be clear from the definition that we have 
Lemma 4. (1) ]= <?. 

(2) For every metric space model ifiM' ^ <P then ^ tp. 

Next we construct M[<F\ and Let 



M{<P) = {a G IR : a occurs in <P}. 
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Denote by 7 the smallest natural number that is greater than all numbers in 
M{<P) U {0} and define M[<P] as 

M['P] = {oi -I h a„ < 7 : ai, . . . , a„ G n < w} U {7} U { 0 }. 

Let /X = min{M(^) — {0}} and let \ be the least natural number such that 
X > 7 /m- An easy (but tedious) computation yields: 

Lemma 5. < \M{<P)\^, whenever |M(<?)| > 2. 

For each location variable x occurring in <^3 we pick a new set variable 
and define 1^3, and by taking 

^3 = {yE 3 <aX^ : 5 {y,z) = a G ^3} U 
{z^X^ : 5 {y,z) = a G <l>3} U 

: 5{y,z) = a £ ^ 3 , b < a, 6 G M[0\}, 

(p' = (Pi \J (p 2 U ^ 3 , 
t{<P) = {t :t G term{<P')}. 

The closure cl{<P) of t{<P) is the smallest set of terms T such that t{<P) C T and 

1. T is closed under subterms; 

2. if t G T, then V<ot G T whenever t is not of the form V<os; 

3. if V<at G T and a > oiH ha„, for Oj G M[(p] — {0}, thenV<ai • ■ G T; 

4 . if V>at G T and b G M[<P], then ^V<h^V>at G T; 

5. if V>at G T and 6 > a, for 6 G M[<P], then V>{,t G T and ^V>h^V>at G T. 

By an easy but tedious computation the reader can check that we have: 

Lemma 6. If \M{<P)\ > 4 and x > 3, then 

\cl{<P)\ < S{^) = \t{<P)\ ■ |M[iZ>]|(^+b-(|M(<f)|-ei) ^ 

We are in a position now to prove the following: 

Theorem 6. <P is satisfied in a metric space model DJt* = (W*, d* , 6*) such that 
|VF*| < 2 • and the range of d* is a subset of M[<P]. 

Proof. We first show that <P is satisfied in a metric space model (W,d', a) with 
the range of d' being a subset of M = M[<P], Indeed, define d' by taking 

d'{w, v) = min{ 7 , a G M : d{w, v) < a}, 

for all w,v G W, and let = (IF, d' , 0 ). Clearly, the range of d' is a subset of M. 
We check that d' is a metric. It satisfies (I) because 0 G M. That d' is symmetric 
follows from the symmetry of d. To show (2), suppose d'{w,v) + d'{v,u) < a, 
for a G M. By the definition of d' , we then have d{w,v) + d{v,u) < a, and so 
d{w,u) < a. Hence d'{w,u) < a. Thus we have shown that 

{a G M : d'{w, v) + d'{v, u) < a} C {a G M : d'{w, u) < a}, 

from which one easily concludes that d'{w,u) < d'{w,v) + d'{v,u). 
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Lemma 7. The set <P is satisfied in 9Jli . 

Proof. Clearly, for each {S{y, z) = a) G d{a{y), 0(2)) = d'{a{y), a(z)) = a. So 
9^1 ^3- To show \= it suffices to prove that 

Vw G WVt G t{$) {wGt^ 

This can be done by a straightforward induction on the construction of t. The 
basis of induction and the case of Booleans are trivial. So suppose t is V<aS (then 
a G M). Then we have: 

w G t^ Vu G IT {d{w, v) < a ^ V G s®') 

<J4>2 Vu G it {d'{w, v) < a ^ V G 
^3W G 

The equivalences and <t^3 are obvious. <J4>2 holds by the induction hypothesis 
and the fact that, for all w,v GW and every a G M, d{x, y) < a iS d'{x, y) < a. 
The case V>aS is considered in a similar way. 

Before filtrating through 0 = cl{'P), we slightly change its assignment. 
Recall that 0 contains the new set variables which function as nominals and 
which will help to fix the distances between the points occurring in <^3. Define b 
to be the assignment that acts as 0 on all variables save the X^, where 

~ b{X^) = {a{z)}. 

Let 9JI2 = {W,d',b). It should be clear from the definition and Lemma 7 that 
we have: 

(a) t^^ = t^^, for all set terms t G t{<P)\ 

(b) 9Jli \= if 9JI2 \= f’, for all formulas if G A4S2(d>); 

(c) DJI 2 h 

(d) 9712 h 

Consider the relational counterpart of DJI 2 , i.e., the model 

©(9JI2) = (ITj (Pa)aeM-, (Pa)aeM, &) 

which, for brevity, will be denoted by ©. Define an equivalence relation = on IT 
by taking u = v when u G t® iff w G t® for all t G 0. Let [u] = {v gW : u = u}. 
Note that if {zgX^) G then [b{z)] = {6(z)}, since G 0. 

Construct a filtration 6-f = (w^ ,{Rl)a^M ,{P^)a&M ^b^^ of 6 through 0 
by taking 

- Wf = {[m] : u G IT}; 

- b^x) = [6(a;)]; 

- bf{X) = {[u]:uGb{X)}-, 

- [f] iff for all terms \/<at G 0, 

• u G {y<at)‘^ implies w G t® and 

• V G (V<at)® implies u G t®; 
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— iff for all terms V>at G 0, 

• u G (V>at)® implies w G and 

• V G (V>at)® implies u G t®. 

Since 0 is finite, is finite as well. Note also that b^(X^) = {b^{z)} whenever 

Lemma 8 . (1) For every t G 0 and every u G W , tt G t® iff [tt] G t®^ . 

(2) For all {S{y, z) = a) G <l> 3 , a = min{5 G M : b^ (y)Rlb^ (z)}. 

(3) satisfies (i), (iii)-(vii) in Section f. 

Proof. (1) is proved by an easy induction on the construction of t. To prove (2), 
take {d{y,z) = a) G d> 3 . We must show that b^ (y)Rfb-^ (z) and ^b-^ (y)R^b^ (z), 
for all a > 6 G M. Notice first that uRaV implies and uRaV implies 

[u]R^[v]. Since 9 Jl 2 |= d>, we have 9 Jl 2 \= = a, and so d'{b{y),b{z)) = 

a. Hence b{y)Rab{z) and b^ (y)Rlb^ {z). Suppose now that b < a and con- 
sider y<b^X^. By definition, b{X^) = { 6 ( 2 )}. Hence b{z) ^ On the 

other hand, we have b < d' {b{y),b{z)), from which b{y) G (V< 6 ^X^)®. Since 
(y<b^X^) G 0 , we then obtain ^b^ {y)R[b^ (z). 

Now let us prove (3). Condition (vii), i.e., iff [u]R[[w], holds by 

definition. 

(i), i.e, R[u RL = Wf X . If then -^uRaV, and so uRaV, since 

& satisfies (i). Thus 

(iii) , i.e., if and a < b then [u]r([v]. Let and a < b, for 

b G M. Suppose u G (V<bt)®. By the definition of 0 = c?(<?), V<at G 0, and so 
u G (V<at)®. Hence u G t®. The other direction is considered in the same way. 

(iv) , i.e., if and a > b then [u]R^[v]. Let and a > b, and 

suppose that u G (V>ht)®. Then V>at G 0, u G (V>at)®, and so u G t®. Again, 
the other direction is treated analogously. 

(v) , i.e., [u]i?Q[u] iff [m] = [u]. The implication (< 1 =) is obvious. So suppose 
[u]r()[v]. Take some t G 0 with m G t®. Without loss of generality we may 
assume that t is not of the form V<os. Then, by the definition of 0, u G (V<ot)® 
and y<ot G 0. Hence u G t®. In precisely the same way one can show that for 
alH G 0, u G t® implies u G t®. Therefore, [u] = [u]. 

(vi) , i.e., if and [v]r[[w], then for (a-|-6) G M. Suppose 

u G (V<a+bt)‘^. Then V<aV<bt G 0 and u G (V<aV<bt)®. Hence w G t®. For 
the other direction, assume w G (V<a-i- 6 t)®. Again, we have V<aV<{,t G 0 and 
w G (V<aV< 6 t)®. In view of (vii) we then obtain u G t®. 

(viii), i.e., if and [u]rI^[w] then [v]R^[w], for (a -I- 6) G M. Sup- 

pose V G ifilybt)^- Then -X<a~X>bt G 0 and u G {~X <a~^ >bt)^ ■ Hence 
u G (V>(a-i-h)t)® and so w G t®. For the other direction, suppose w G (V>ht)®. 
Then u G (^V>(a-i- 6 )^V> 6 t)® and ^V>(a+f,)^V>bt G 0. Hence u G (V<at)® and 
so u G t®. 
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Unfortunately, does not necessarily satisfy (ii) which is required to con- 
struct the model we need: it may happen that for some points [u], [u] in 
and a G M, we have both [u]i?£[u] and [u]R^[v]. To ‘cure’ these defects, we have 
to perform some surgery. The defects form the set 

D(W^) = {d € : 3a G M3x G {xRld & xR^d)}. 



Let 



W* = {(d,i) :d€B(W^),i€ {0, 1}} U {(c, 0) : c G - B(W^)j. 

So for each d G B(W^) we have now two copies (d,0) and (d,l). Define an 
assignment 6* in W* by taking 

— &*(a:) = (6^(a:),0) and 

— 6*(X) = {(c,i) G lU* : c G hf{X)). 

Finally, we define accessibility relations i?* and as follows: 

— if a > 0 then (c, i) i?* (d, j) iff either 

• ci?^d and ~^cR^d, or 

• cR[d and i = j; 

— if a = 0 then (c, i) i?* {d, j) iff (c, z) = (d, j) ; 

— R^ is defined as the complement of R*, i.e., (c, z) (d, j) iff ^ (c, z) R* {d,j). 



Lemma 9. 6* = {W* , {Rl)a^M , {R^)a^ M, &*) is an M-standard relational met- 
ric model. 

Proof. That ©* satisfies (i), (ii), and (v) follows immediately from the definition. 
Let us check the remaining conditions. 

(iii) Suppose (c, z) R* {d,j) and a < b G M. If z = j then clearly (c, z) Rl {d,j). 
So assume i ^ j. Then, by definition, cR^d and -^cR^d. Since ©^ satisfies (iii) 
and (iv), we obtain cR[d and ~^cR^d. Thus {c,i)Rl {d,j). 

(iv) Suppose that (c, z) (d, j) and a > b G M, but ^ (c, z) (d, j). By (i), 
(c,i) Rl{d,j). And by (iii), {c, i) Rl {d, j) . Finally, (ii) yields ^ (c,i) Rl;{d,j), 
which is a contradiction. 

(vi) Suppose (c, z) i?* (d, j), (d, j) Rl (e, k) and a -I- 5 G M. Then cR[d and 

dR[e. As satisfies (vii), we have If z = A: then clearly (c, z) (e, k). 

So assume i ^ k. If i = j ^ k then -ncRt—e, since cRfd and ^dRle. The case 

i ^ j = k is considered analogously using the fact that the relations in ©-^ are 
symmetric. 

(vii) follows from the symmetry of R[ and R^. 



Lemma 10. For all {d,i) G W* and t G 0, we have {d,i) G ijf d G t®'^ . 
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Proof. The proof is by induction on t. The basis of induction and the case of 
Booleans are trivial. The cases t = (V<as) and t = (V>as) are consequences of 
the following claims: 

Claim 1: if cR[d and i G {0, 1}, then there exists j such that (c,i) Rl {d,j). 
Indeed, this is clear for z = 0. Suppose z = 1. If d was duplicated, then (d, 1) is 
as required. If d was not duplicated, then -^cR^d, and so (d, 0) is as required. 
Claim 2: if (c, z) i?* (d, j) then cR[d. This is obvious. 

Claim 3: if cR^d and z G {0, 1} then there exists j such that ^ (c, z) i?* (d, j). 
Suppose z = 0. If d was not duplicated, then -^cR[d. Hence ^ (c, 0) i?* (d, 0). If d 
was duplicated, then ^ (c, 0) R* (d, 1). In the case z = 1 we have ^ (c, I) i?* (d, 0). 

Claim C- if ^ (c, *) Rf {d,j) then cR^d. Indeed, if z = j then ^cR[d and so 
cR^d. And if z yf j then cR^d. 

To complete the proof of Theorem 6, we transform ©* into a finite metric 
space model and show that this model satisfies <P. Put = (VP*, d*, 6*), where 
for all w,v € W*, 

d* (w, v) = min{^, a G M : wR*v}. 

As M is finite, d* is well-defined. Using (v)-(vii), it is easy to see that d* is a 
metric. So 201* is a finite metric space model. It remains to show that 201* satisfies 
d>. Note first that 

(t) for all w G W* and t G we have w G t®* iff zc G t®'*. 

This claim is proved by induction on t. The basis and the Boolean cases are 
clear. So let t = (V<as) for some a G M. Then 

w G (V<as)® Vz; {wR’^v ^ u G s® ) 

Vu {wR*v ^ V G ) 

Vu {d*{w, v) < a ^ V G ) 

<^4W G (V<aS)®' . 

Equivalences and are obvious; holds by the induction hypothesis; 
< 1=3 is an immediate consequence of the definition of d*, and = 1<3 follows from 
(iii). The case t = (V>as) is proved analogously. 

We can now show that \= <P. Let (xEt) G Then we have: 

201* \= x^t 6*(a:) G t®'* <t ^2 G t®* <t ^3 (6-f(a;),0) G t®* <t ^4 
b^{x) G t®'^ <t ^5 [&(a;)] G t®'^ <t^6 ^ "^7 ^ "^8 |= x^t. 

Equivalences <t^i and are obvious; <t ^2 follows from (f); <14>3 and <t^s hold 
by definition; <^4 follows from Lemma 10, <14>6 from Lemma 8, and <14>7 from 
Lemma 3. 

Since 2 OI 2 [= we have 201* ^ <Pi. That 201* ^ ^2 is proved analogously 
using (t). 
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It remains to show that \= ^3. Take any S{y, z) = a from ^3. We must 
show that d*{b*{y), &*(^)) = a. By Lemma 8 (2), 

a = min{b G M : 

So a = min{b G M : (b^{y),0) Rl (6-^(2), O)}. By the definition of 6* we have 
a = min{b G M : b*{y)Rlb*{z)}, which means that d*{b*{y), b*{z)) = a. 

This completes the proof of Theorem 6. 

Thus, by Theorem 6 and Lemma 4 (2), ip is satisfied in the finite model 
Yet this is not enough to prove the decidability of AI52[Q]: we still do not 
know an effectively computable upper bound for the size of a finite model sat- 
isfying ip. Indeed, the set M{<P) depends not only on p, but also on the initial 
model satisfying p. Note, however, that by Lemmas 5 and 6 the size of 
can be computed from the maximum of M(<P), the minimum of M(<P) — {0}, 
and p. Hence, to obtain an effective upper bound we need, it suffices to start the 
construction with a model satisfying p for which both the maximum of M{<P) 
and the minimum of M{<P) — {0} are known. The next lemma shows how to 
obtain such a model. 

Lemma 11. Suppose a formula p G A452[Q] is satisfied in a metric space model 
(IT, d, 0). Denote by V the set of all S(x, y) occurring in p, and let a and b be the 
minimal positive number and the maximal number occurring in p, respectively 
(if no such number exists, then put a = b = 1). Then there is a metric d' on W 
such that p is satisfied in {W,d', 0) and 

min{d'(o(a:), a(y)) > 0 : S{x,y) G D} > a/2, 
max{d'(o(a;), a(y)) : S{x,y) G D} < 2b. 

Proof. Let 

a' = min{d(a(a:), a{y)) > 0 : S{x, y) G T>}, 
b' = max{d(o(a:), a{y)) : 8{x, y) G V}. 

We consider here the case when a' < a /2 and 2b < b' . The case when this is not 
so is easy; we leave it to the reader. Define d' by taking 

{ d{x, y) if a < d{x, y) <b or d{x, y) = 0, 

b + (6/ (6' - b)) ■ (d(x, y) - b) if d{x, y) > b, 
a + {a/2{a — a')) ■ {d{x, y) — a) if 0 < d{x, y) < a. 

One can readily show now that d' is a metric and (W, d' , 0) satisfies p. 

6 Weaker Distance Spaces 

As was mentioned in Section 1, our everyday life experience gives interesting 
measures of distances which lack some of the features characteristic to metric 
spaces. Not trying to cover all possible cases, we list here some possible ways of 
defining such alternative measures by modifying the axioms of standard metric 
spaces: 
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— we can omit either the symmetry axiom or the triangular inequality; 

— we can omit both of them; 

— we can allow fi to be a partial function satisfying the following conditions 
for all w,v,u & W , where dom{d) is the domain of d\ 

• (w,w) G dom{d) and d{w,w) = 0, 

• if {w, v) G dom{d) and d{w, v) = 0, then w = v, 

• if (w,v) G dom(d) and (v,u) G dom(d), then {w,u) G dom{d) and 
d{w, u) < d{w, v) + d{v, u), 

• if (w,v) G dom{d), then (v,w) G dom{d) and d{w,v) = d{v,w). 

Using almost the same techniques as above one can generalize the obtained 
results on the decidability and finite model property of A4S2 to these weaker 
metric spaces as well. 
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Abstract. In this paper we show the embedding of Hybrid Probabilis- 
tic Logic Programs into the rather general framework of Residuated 
Logic Programs, where the main results of (definite) logic programming 
are validly extrapolated, namely the extension of the immediate conse- 
quences operator of van Emden and Kowalski. The importance of this 
result is that for the first time a framework encompassing several quite 
distinct logic programming semantics is described, namely Generalized 
Annotated Logic Programs, Fuzzy Logic Programming, Hybrid Proba- 
bilistic Logic Programs, and Possibilistic Logic Programming. Moreover, 
the embedding provides a more general semantical structure paving the 
way for defining paraconsistent probabilistic reasoning logic program- 
ming semantics. 



1 Introduction 

The literature on logic programming theory is brimming with proposals of lan- 
guages and semantics for extensions of definite logic programs (e.g. [7,15,4,10]), 
i.e. without non-monotonic or default negation. Usually, the authors character- 
ize their programs with a model theoretic semantics, where a minimum model is 
guaranteed to exist, and a corresponding monotonic fixpoint operator (continu- 
ous or not). In many cases these semantics are many- valued. 

In this paper we start by defining a rather general framework of Residuated 
Logic Programs. We were inspired by the deep theoretical results of many- valued 
logics and fuzzy logic (see [1,9] for excellent accounts) and applied these ideas 
to logic programming. In fact, a preliminary work in this direction is [15], but 
the authors restrict themselves to a linearly ordered set of truth-values (the real 
closed interval [0,1]) and to a very limited syntax: the head of rules is a literal and 
the body is a multiplication (t-norm) of literals. Our main semantical structures 
are residuated (or residual) lattices (c.f. [1,9]), where a generalized modus ponens 
rule is defined. This characterizes the essence of logic programming: from the 
truth-value of bodies for rules for an atom we can determine the truth-value of 
that atom, depending on the confidence in the rules. 
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Besides fuzzy reasoning, probabilistic reasoning forms are essential for knowl- 
edge representation in real-world applications. However, a major difficulty is that 
there are several logical ways of determining the probabilities of complex events 
(conjunctions or disjunctions) from primitive ones. To address this issue, a model 
theory, fixpoint theory and proof theory for hybrid probabilistic logic programs 
were recently introduced [4,3] . The generality of Residuated Logic Programming 
is illustrated in practice by presenting an embedding of Hybrid Probabilistc Logic 
Programs [4,3] into our framework. 

Our paper proceeds as follows. In the next section we present the residuated 
logic programs. Afterwards, we overview the hybrid probabilistic logic program- 
ming setting and subsequently provide the embedding. We finally draw some 
conclusions and point out future directions. We included the main proofs for the 
sake of completeness. 

2 Residuated Logic Programs 

The theoretical foundations of logic programming were clearly established 
in [11,14] for definite logic programs (see also [12]), i.e. programs made up of 
rules of the form Aq C Ai A . . . A A„(n > 0) where each Ai(0 < f < n) is a propo- 
sitional symbol (an atom), C is classical implication, and A the usual Boolean 
conjunction^. In this section we generalize the language and semantics of defi- 
nite logic programs in order to encompass more complex bodies and heads and, 
evidently, multi-valued logics. For simplicity, we consider only the propositional 
(ground) case. 

In general, a logic programming semantics requires a notion of consequence 
(implication) which satisfies a generalization of Modus Ponens to a multi-valued 
setting. The generalization of Modus Ponens to multi-valued logics is very well 
understood, namely in Fuzzy Propositional Logics [13,1,9]. Since one of our initial 
goals was to capture Fuzzy Logic Programming [6,15], it was natural to adopt 
as semantical basis the residuated lattices (see [5,1]). This section summarizes 
the results fully presented and proved in [2]. We first require some definitions. 

Definition 1 (Adjoint pair). Let < P,<p> he a partially ordered set and 
(^, ®) a pair of binary operations in P such that: 

(ai) Operation 0 is isotonic, i.e. if x\,X 2 ,y G P such that xi Ap X 2 then 
(a^i ® y) Ap {x 2 ® y) and {y (g) x\) Ap [y (g> 0 : 2 ); 

( 02 ) Operation <— is isotonic in the first argument (the consequent) and antitonic 
in the second argument (the antecedent), i.e. ifx\,X 2 ,y G P such thatxi Ap 
X 2 then {xi ^ y) Ap (x 2 ^ y) and {y ^ X 2 ) <p {y ^ xi); 

( 03 ) For any x,y,z G P, we have that x Ap (y <— z) holds if and only if 
(x 0 z) Ap y holds. 

Then we say that (<— , (g>) forms an adjoint pair in < P, Ap>. 

^ We remove the parentheses to simplify the reading of the rule. 
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The intuition of the two above properties is immediate, the third one may be 
more difficult to grasp. In one direction, it is simply asserting that the following 
Fuzzy Modus Ponens rule is valid (cf. [9]): 

If a; is a lower bound of r/; <— (p, and z is a lower bound of tp then a lower 
bound y of tp is X ^ z. 

The other direction is ensuring that the truth-value of y <— a: is the maximal z 
satisfying x ^ z y. 

Besides (ai)-(a 3 ) it is necessary to impose extra conditions on the multiplica- 
tion operation (0), namely associativity, commutativity and existence of a unit 
element. It is also indispensable to assume the existence of a bottom element in 
the lattice of truth- values (the zero element). Formally: 

Definition 2 (Residuated Lattice). Consider the lattice < We say 

that (L-,<— ,0) is a residuated lattice whenever the following three conditions 
are met: 

(li) < L, <L> is a hounded lattice, i.e. it has bottom (T) and top (T) elements; 
(h) (<— , <8>) is an adjoint pair in < L, <l>; 

{I 3 ) (L, (g), T) is a commutative monoid. 

We say that the residuated lattice is complete whenever < L, <l> is complete. 
In this case, condition (h) is immediately satisfied. 

Our main semantical structure is a residuated algebra, an algebra where a 
multiplication operation is defined, the corresponding residuum operation (or 
implication), and a constant representing the top element of the lattice of truth- 
values (whose set is the carrier of the algebra). They must define a complete 
residuated lattice, since we intend to deal with infinite programs (theories). Ob- 
viously, a residuated algebra may have additional operators. Formally: 

Definition 3 (Residuated Algebra). Consider a algebra fH defining opera- 
tors <— ,0 and T on carrier set Tty, such that is a partial order on Ty. We 
say that iR is a residuated algebra with respect to (<— , O) if (T^, , O) is a com- 

plete residuated lattice. Furthermore, operator T is a constant mapped to the top 
element ofTy. 

Our Residuated Logic Programs will be constructed from the abstract syntax 
induced by a residuated algebra and a set of propositional symbols. The way of 
relating syntax and semantics in such algebraic setting is well-known and we 
refer to [8] for more details. 

Definition 4 (Residuated Logic Programs). Let iR be a residuated algebra 
with respect to (^,0,T). Let II he a set of propositional symbols and the cor- 
responding algebra of formulae 'S freely generated from 77. A residuated logic 
program is a set of weighted rules of the form {{A ^ F), d) such that: 

1. The rule {A ^ F) is a formula of 

2. The confidence factor d is a truth-value o/fH belonging to 
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3. The head of the rule A is a propositional symbol of U. 

4- The body formula T corresponds to an isotonic function with propositional 
symbols B\, . . . , Bn (n >0) as arguments. 

To simplify the notation, we represent the above pair as A < — T[Bi, . . . ,Bn], 
where B\, . . . ,B„ are the propositional variables occurring in T. Facts are rules 
of the form A T. 

A rule of a residuated logic program expresses a (monotonic) computation 
rule of the truth-value of the head propositional symbol from the truth-values 
of the symbols in the body. The monotonicity of the rule is guaranteed by iso- 
tonicity of formula F: if an argument of F is monotonically increased then the 
truth-value of F also monotonically increases. 

As usual, an interpretation is simply an assignment of truth-values to every 
propositional symbol in the language. To simplify the presentation we assume, 
throughout the rest of this section, that a residuated algebra fH is given with 
respect to (^, 0, T). 

Definition 5 (Interpretation). An interpretation is a mapping I : II ^ T^. 
It is well known that an interpretation extends uniquely to a valuation function I 
from the set of formulas to the set of truth values. The set of all interpretations 
with respect to the residuated algebra fH is denoted by T^. 

The ordering ^ of the truth- values 7^ is extended to the set of interpretations 
as usual: 

Definition 6 (Lattice of interpretations). Consider the set of all interpreta- 
tions with respect to the residuated algebra fH and the two interpretations I\,l 2 € 
T^. Then, < 2fR,E> is a complete lattice where I\ C I 2 iff\/p^n Ii{p) A hip)- 
The least interpretation A maps every propositional symbol to the least element 
of%n. 

A rule of a residuated logic program is satisfied whenever the truth- value of 
the rule is greater or equal than the confidence factor associated with the rule. 
Formally: 

Definition 7. Consider an interpretation I € X^r. A weighted rule {{A ^ F) , D) 
is satisfied by I iff I {{A ^ F)) ^ d. An interpretation I G Tty^ is a model of a 
residuated logic program P iff all weighted rules in P are satisfied by I. 

Mark that we used I instead of / in the evaluation of the truth-value of a rule, 
since a complex formula is being evaluated instead of a propositional symbol. If 
<— 9 ^ is the function in fH defining the truth-table for the implication operator, 
the expression / ((A ^ iF)) is equal to 

i{A) = i{A) 

The evaluation of /('?') proceeds inductively as usual, till all propositional sym- 
bols in F are reached and evaluated in I. 
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The immediate consequences operator of van Emden and Kowalski [14] is 
extended to the very general theoretical setting of residuated logic programs as 
follows: 

Definition 8. Let P be a residuated logic program. The monotonic immediate 
consequences operator Tp : I<y\ Iiy\, mapping interpretations to interpreta- 
tions, is defined by: 

Tp{I){A) = lub (8> I{T') such that A ^ T[Bi , . . . , S„] G p| 

As remarked before, the monotonicity of the operator Tp has been shown 
in [2]. The semantics of a residuated logic program is characterized by the post- 
fixpoints of T|?: 

Theorem 1. An interpretation I of Tty, is a model of a residuated logic program 
P iffT^{I) C I. Moreover, the semantics of P is given by its least model which 
is exactly the least fixpoint ofTp. The least model of P and can be obtained by 
trasfinitely iterating Tp from the least interpretation A. 

The major difference from classical logic programming is that our Tp may 
not be continuous, and therefore more than oj iterations may be necessary to 
reach the least fixpoint. This is unavoidable if of one wants to keep generality. 
All the other important results carry over to our general framework. 



3 Hybrid Probabilistic Logic Programs 

In this section we provide an overview of the main definitions and results in [4,3]. 
We do not address any of the aspects of the proof theory present in these works. 
A major motivation for the Hybrid Probabilistic Logic Programs is the need for 
combining several probabilistic reasoning forms within a general framework. To 
capture this generality, the authors introduced the new notion of probabilistic 
strategies. 

A first important remark is that the probabilites of compound events may be 
closed intervals in [0, 1], and not simply real- valued probability assignments. The 
set of all closed intervals of [0,1] is denoted by C[0, 1]. Recall that the empty set 
0 is a closed interval. In C[0, 1] two partial-orders are defined. Let [a, b] G C[0, 1] 
and [c, d\ G C[0, 1], then: 

— [a, b] <t [c, d] if a < c and b < d, meaning that [c, d] is closer to 1 than [a, b]. 

— [a, b] C [c, d] if c < a and b < d, meaning that [a, b] is more precise than 
[c,d]. 

The probabilistic strategies must obey the following natural properties: 

Definition 9 (Probabilistic strategy). A p-strategy is a pair of functions 
p =< c, md > such that: 
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1 . c : C[0,1] X C[0,1] ^ C[0,1] is called a probabilistic composition function 
satisfying the following axioms: 

Commutativity: c([ai, 6i], [a2, 62]) = c([a2, 62], [ai, &i]) 

Associativity: c(c([ai,6i], [02,62]), [03,63]) = c([oi, 61], c([o2, 62], [03,63])) 
Inclusion Monotonicity: //[oi,6i] C [03,63] then c([oi, 61], [02, 62]) C 
c( [03,63], [02,62]) 

Separation: There exist two functions c^,c^ : [0,1] x [0,1] ^ [0,1] such 
that c([o, 6], [c, d]) = [c^(o, c), c^(6, d)]. 

2 . md : C[0, 1] ^ C[0, 1] is called a maximal interval function. 

The strategies are either conjuntive or disjunctive: 

Definition 10. A p-strategy < c,md > is called a conjunctive (disjunctive) p- 
strategy if it satisfies the following axioms: 





Conjunctive p-strategy 


Disjunctive p-strategy 


Bottomline 


c([ai, 61], [02,62]) <t 
[TOzn(oi, 02), TOzn(6i, 62)] 


[max{ai,a2), max{bi, 62)] 
<t c([oi,6i], [02,62]) 


Identity 


c([o,6],[l,l]) = [o,6] 


c([o,6], [0,0]) = [0,6] 


Annihilator 


c([o,6],[0,0]) = [0,0] 


c([o,6], [1, 1]) = [1, 1] 


Max. Interval 


md{[a, 6]) = [0, 1]) 


md{[a, 6]) = [0, 6] 



The syntax of hybrid probabilistic logic programs (hp-programs) is built on 
a first-order language L generated from finitely many constants and predicate 
symbols. Thus, the Herbrand base Bl of L is finite. Without loss of generality, 
we restrict the syntax to a propositional language: variables are not admitted in 
atoms. This simplifies the embedding into residuated logic programs. 

In a hp-program one can use arbitrary p-strategies. By definition, for each 
conjunctive p-strategy the existence of a corresponding disjunctive p-strategy is 
assumed, and vice-versa. Formally: 

Definition 11. Let CONj be a finite set of coherent conjunctive p-strategies 
and DISJ be a finite set of coherent disjunctive p-strategies. Let C denote 
CONj U VTSJ. Lf p G CON J then connective Ap is called a p-annotated 
conjunction. If p G VTSJ then \J p is called a p-annotated disjunction. 

The elementary syntactic elements of hp-programs are basic formulas: 

Definition 12. Let p be a conjunctive p-strategy, p' be a disjunctive p-strategy 
and Ai, ... , be atoms. Then Ai Ap A2 Ap . . . Ap and Ai Vp' A2 Vp' . . . Vp' Ak 

are hybrid basic formulas. Let bfp(BL) denote the set of all ground hybrid basic 
formulas for a connective. The set of ground hybrid basic formulas is bfc = 
'Specbfp(BL). 

Basic formulas are annotated with probability intervals. Here we differ 
from [4] where basic formulas can be additionally annotated with variables and 
functions. 
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Definition 13. A hybrid probabilistic annotated basic formula is an expression 
of the form B : p, where B is a hybrid basic formula and G C[0, 1]. 

Finally, we can present the syntax of hybrid rules and hp-programs: 

Definition 14. A hybrid probabilistic program over the set C of p-strategies is 
a finite set of hp-clauses of the form Bg : po ^ Bi : pi A ... A Bk '■ Pk where 
each Bi : pi is a hp-annotated basic formula over C. 

Intuitively, an hp-clause means that “if the probability of B\ falls in the 
interval pi and . . . and the probability of Bk falls within the interval pk, then 
the probability of Bq lies in the interval /to” . Mark that the conjunction symbol 
A in the antecedent of hp-clauses should be interpreted as logical conjunction 
and should not be confused with a conjunctive p-strategy. 

The semantics of hp-programs is given by a fixpoint operator. Atomic func- 
tions are akin to our notion of interpretation and are functions / : B^ C[0, 1]. 
They may be extended to hybrid basic formulas. For this the notion of splitting 
a formula into two disjoint parts is necessary:: 

Definition 15. Let F = F\*p. . .*pFn, G = Gi*p. . .*pGk, H = . .*pHm 

where * G {A, V}. We write G (Bp H = F iff 

1. {Gi,... ,Gfc}U{ili,...,il™} = {Fi,... ,F„}, 

{Gi,... ,Gfc}n{lli,...,il™} = 0 , 

3. k > 0 and m > 0. 

The extension to atomic formulas is as follows: 

Definition 16. A hybrid formula function is a function h : bfciB^) C[0, 1] 
which satisfies the following properties: 

1. Commutativity. If F = G\ 0p G 2 then h{F) = h{Gi *p G 2 ). 

2. Composition. If F = G\ ©p G 2 then h{F) C Cp{h{Gi), h{G 2 )). 

3. Decomposition. For any basic formula F, h{F) C mdp{h{F *p G) for all 
p G C and G G bfciBif). 

Let hi and /12 be two hybrid formula functions. We say that h\ < /12 iff (VF’ G 
bfciBr)) h\{F) D / 12 (A). In particular, this means that there is a minimum 
element of hiFF mapping every hybrid basic formula to [0, 1]. 

The immediate consequences operator for hp-programs resorts to the follow- 
ing auxiliary operator. Again, we consider the ground case only: 

Definition 17. let P be a hp-program. Operator Sp : HFF HFF is defined 
as follows, where F is a basic formula. Sp{h){F) = DM where M = {p\F : p ^ 
Fi : piA. . .AFn : Pn is an instance of some hp-clause in P and (Vj < n) h{Fj) C 
Pj}. Obviously, if M = 0 then Sp{h){F) = [0,1]. 

Definition 18. Let P be a hp-program. Operator Tp : TIFF TIFF is defined 
as follows: 
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1. Let F he an atomic formula. 

(a) if Sp{h){F) = 0 then Tp{h){F) = 0. 

(b) if Sp{h){F) 7^ 0 then let M = {< n, p > |(F 0p G) : p, ^ Fi : pi A ... A 

Fn : Pn where * € {V, A}, p & L and (\/j < n) h{Fj) C pj^\. We define 

Tp{h){F) = {f\{mdp{p)\ < p, p >G M}) n Sp{h){F) 

2. If F is not atomic, then 

Tp{h){F) = Sp{h){F)n{n{cp{Tp{h){G),Tp{h){H)) \ G®H = F})n 
{{mdp{p)\ < p,p>G M}) 

where M = {< p, p >\ Di *p . . . *p Dk : p <— Ei : pi A ... A '. 

Pm such that (Vj < n) h{Ej) C pj and 3 hE (Bp FI = {D\, . . . , 

A full explanation and intuition of the above operators can be found in [4]. 
Mark that the interval intersection operator H in operators Sp and Tp corre- 
sponds to the join operation in lattice G[0, 1] ordered by containment relation 
A. For the continuation of our work it is enough to recall that the Tp opera- 
tor is monotonic (on the containment relation) and that it has a least fixpoint. 
Furthermore, the least model of a hp-program is given by the least fixpoint of 
Tp. We will base our results in these properties of the Tp operator. We end this 
section with a small example from [4], adapted to the ground case. 

Example 1. Assume that if the CEO of a company sells the stock, retires with 
the probability over 85% and we are ignorant about the relationship between the 
two events, then the probability that the stock of the company drops is 40-90%. 
However, if the CEO retires and sells the stock, but we know that the former 
entails the latter, then the probability that the stock of the company will drop 
is only 5-20%. This situation is formalized with the following two rules: 

price-drop: [0.4, 0.9] ^ (ch-sells-stock Aigc ch-retires):[0.85,l] 
price-drop: [0.05,0.2] ^ (ch-sells-stock Apcc ch-retires):[l,l] 

Where Aigc is a conjunctive ignorance p-strategy with Cigc{[a\, 6i], [02, 62]) = 
[moa:(0, oi -I-02 — l),min(bi, 62)], and Apcc is the positive correlation conjunctive 
p-strategy such that Cpcc([ai, 61], [02,62]) = [mtn(oi, 02), min(6i, 62)]. 

Now assume we have the two facts ch-sells-stock: [1,1] and ch-retires: [0.9,1]. 
In this case, we obtain in the model of P that the probability of price-drop is in 
[0.4, 0.9] since the first rule will fire and the second won’t. If instead of the above 
two facts we have (ch-sells-stock Aigc ch-retires) : [1 , 1] then in the least fixpoint 
of Tp price- drop will be assigned 0. 

4 Embedding of Hybrid Probabilistic Logic Programs 
into Residuated Logic Programs 

In this section we present the embedment result. This will require some effort. 
First, we need to define our underlying residuated lattice. We will not restrict 
ourselves to closed intervals of [0,1]. We require additional truth- values: 




Hybrid Probabilistic Logic Programs as Residuated Logic Programs 



65 



Definition 19. Let ZA/”T be the set of pairs formed from values in [0,1]. We 
represent a value < a, b >G 2NT by [a,b]. We say that [ai, 6 i] < [ 02 , 62 ] iff 
ai < 02 and 62 < 61. 

A pair [o, 6] in XAfT (with a < b) represents a non-empty closed interval of 
C[0, 1]. The intuition for the remaining “intervals” of the form [c, d] with c > d 
will be provided later on, but we can advance now that they represent a form of 
inconsistent probability intervals. They correspond to 0 in (7[0, 1]. The relation 
< on XAfT forms a partial order, and extends the containment relation of C”[0, 1] 
to XNT. In particular, [0,1] and [1,0] are, respectively, the least and greatest 
elements of TAfT. These remarks are justified by the following two results: 

Proposition 1. The set lAfT with the partial order forms a complete lattice 
with the following meet and join operators: 

[ai,6i] n [02,62] = [mm(ai, 02), moa:(6i, 62)] 

[oi, 61] U [02, 62] = [moa:(ai, 02), TOzn(6i, 62)] 

In general, consider the family {[0^,6^]}^^^ then 

ni^i[ai,bi\ = [inf {oi \ i G I},sup{bi | z G /}] 

Uig/[ai,6j] = [sup{ai \ i G J},zn/{6i | z G /}] 



Proposition 2. Consider the mapping ■ from TAfT to C[0, 1] such that [a, 6] = 
[a, 6] if a <b, otherwise it is 0. Let [oi,6i] and [02,62] belong to C[0, 1]. Then, 

[oi, 61] n [02, 62] = [oi, 61] U [o2, 62] 



Example 2. Consider the intervals [0.5, 0.7] and [0.6, 0.9]. Their intersection is 
[0.6, 0.7] which is identical to their join in lattice TAfT. Now, the intervals 
[0.5, 0.7] and [0.8, 0.9] have empty intersection. However their join is [0.8, 0.7]. 
This will mean that there is some inconsistency in the assignment of probability 
intervals. In fact, we know that there is a gap from [0.7, 0.8]. Thus, [0.8, 0.7] is 
0 . 

The interpretation is a little more complex when more than two intervals are 
involved in the join operation. The intersection of [0.1, 0.2], [0.4, 0.6] and [0.7, 0.9] 
is empty again. Their join is [0.7, 0.2], meaning that the leftmost interval ends 
at 0.2 while the rightmost begins at 0.7. Again, [0.7, 0.2] = 0. 

We have seen that the meet and join operations perform the union and in- 
tersection of “intervals” of TAfT, respectively. Our objective is to construct a 
residuated lattice from TAfT and the meet operation, which will be the multi- 
plication operation. The adjoint residuum operation (implication) is defined as 
follows: 
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Definition 20. Let [ai,6i] and [02,62] belong tolMT. Then: 



[oi,6i] ^ [02,62] 



[1,0] i/ 02 < oi and 62 > 61 
[ 1 ,61] if 02 < oi and 62 < 61 
[oi, 0 ] if 02 > oi and 62 > 61 
[oi,6i] if 02 > oi and 62 < 61 



The result of the residuum operation is not obvious but still intuitive. In 
fact, we are testing whether [02,62] contains [oi,6i] (i.e. if [oi,6i] > [02,62]) 
and how [02, 62] should be extended in order to satisfy the inclusion. If the first 
(second) component of [oi,6i] ^ [02,62] is 1 (respectively 0) we do not have to 
do anything to [02, 62]. Otherwise, 02 (resp. 62) should be reduced (increased) to 
oi (61). Notice again that [1,0] is our top element in lattice XNT. 

Theorem 2. The operations (^,n) form an adjoint pair in the partially or- 
dered set < XAfT, <>. 



Clearly, the structure < XAfT, □ > is a complete residuated lattice, with 
top element [1,0]. A corresponding residuated algebra is easily constructed. We 
proceed by presenting a result which will enable the embedding of hybrid prob- 
abilistic logic programs into residuated logic programs: 

Theorem 3. Consider the operator Tp which is identical to Tp except for when 
its argument formula F is not atomic; then: 

T'p{h){F) = Sp{h){F) n (n {cp(/i(G), h{H)) \ G®H = F})r\ 
({mdp(^)| < >G M}) 



with M defined as before. Then h is a fixpoint ofTp iff h is a fixpoint ofTp. 

Proof: The only difference between the operators is that we have replaced 
Cp(Tp{h){G), Tp{h){H)) in Tp by Cp{h{G), h{H)) in Tp. Clearly, if /i is a fixpoint 
of Tp then it is also a fixpoint of Tp, since h = Tp{h) we can substitute h by 
Tp(h) in the definition of Tp getting Tp. For the other direction, we prove the 
result by induction on the number of atoms in F. If F is atomic then Tp(h) = 
Tp(Ji), by definition. Otherwise, F is not an atomic formula. Since /i is a fixpoint 
of Tp we have: 



T'p{h){F) = Sp{h){F) n (n {cp{h{G), h{H)) \G®H = F})C 
({mdp(/i)| < /i,p >G M}) 

= Sp{h){F) n (n {cp{T'p{h){G), T'p{h){H)) I G © F6 = T}) n 
({mdp(/r)| < >G M}) 

But clearly G and FI have a smaller number of atoms. So, from the induction hy- 
pothesis we know that T'p{h){G) = Tp{h){G) and Tp{h){H) = Tp{h){H). Sub- 
stituting these equalities into the above equation we get Tp{h){F) = Sp{h){F)r\ 
{n{cp(Tp{h){G),Tp{h){H)) \G® H = F}) n {{mdp{p,)\ < p,, p >€ M}) which 
is Tp{h){F). □ 
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Before we present the embedding, we need some auxiliary functions in TAfT : 



Definition 21. The double bar function ■ fromXMT to TNT and the functions 
Sfi : TNT TNT where /x in TNT are defined as follows: 



( [1,0], if a>b 
\ [a,b], otherwise. 






[1,0], if 

[0, 1], otherwise. 



The above functions are clearly monotonic. Furthermore, the s^ functions 
are “two- valued” and will be used to perform the comparisons in the rule bodies 
of a probabilistic logic program. Now, the embedding is immediate: 



Definition 22. Consider the hp-program P on the set of p- strategies L. First, 
we construct the residual algebra J from the carrier set TNT, and operations 
n, Cp{p G L), Sp{pi G TNT), the double bar function, and the top constant [1,0]. 
Next, we build the residuated logic program Php from P as follows, where every 
ground hybrid basic formula in bfc is viewed as a new propositional symbof in 
the language of Php. 



1. For each rule in P of the form F \ p, ^ F\ : pi A ... A F^ : pk we add to Php 

the rule^ F < < Sp„ n . . . n . 

2. For every, F , G, and H in bfc such that FI = F®pG, and p is a conjunctive 
p-strategy, then for every rule FI : [a,b] ^ Ei : pi A ... A Em : Pm in P we 

add to Php the rule F : ‘ n . . . n Sp^ (^Emi^ . 

3. For every, F , G, and FI in bfc such that H = F(BpG, and p is a disjunctive 
p-strategy, then for every rule FI : [a,b] ^ Ei : pi A ... A Em : Pm in P we 

add to Php the rule F Sp^^ n • • • n Sp^ (Em\ ■ 



I 



Finally, for every F, G, and FI in bfc such that F 

[ 1 , 0 ] /= =\ 

in Php the rule F ^ Cp [G, Fd \ . 



G (Bp H then include 



Some remarks are necessary to fully clarify the above translation. First, the Cp 
functions were previously defined on domain C[0, 1]. It is required to extend them 
to TNT . For elements of TNT isomorphic to elements of C[0, 1] the functions 
should coincide. For values in TNT not in C[0,1] the functions Cp can take 
arbitrary values, since in the embedding the arguments of these functions always 
take values from C[0, 1]. 

Also, the above translation produces a residuated logic program. The rules 
belong to the algebra of formulae freely generated from the set of propositional 

^ Without loss of generality, we assume that the ocurrences of atoms in each hybrid 
basic formula are ordered according to some total order in the set of all atoms. 

® We assign to the body of translated facts the top constant [1, 0]. 
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symbols and operators in the corresponding residual algebra. Thus, when eval- 
uating F ^ n . . . n Sfif. (Pk) with respect to interpretation / we really 



n . . . n s„ 



, as usual. It should be clear that 



uating F ^ respect to interpretation I we really 

mean I{F) ^ □ . . . □ as usual. It should be clear that 

every body formula is isotonic on its arguments: for the first three types of rules 
the body is the composition of isotonic functions and therefore the resulting 
function is also isotonic. The probabilistic composition functions are isotonic by 
definition (check Definition 9). 

The rules introduced in the fourth step are exponential in the number of 
atoms (width) in F. This is expected since it is known that the computation of 
the least fixpoint of an HPP is exponential in the width of the largest formula 
of interest, as shown in [3]. The complexity of the entailment and consistency 
problems for HPPs are more subtle and the reader is referred again to [3] for 
these profound results. 



Theorem 4. Let P he a hybrid probabilistic logic program and Php the corre- 
sponding residuated logic program overJ. Let h he the least fixpoint ofTp^^ and 

F he the least fixpoint ofTp. Then, for every F in bfc, we have h'{F) = h{F). 



Proof: We will prove that for every F in bfc we have Tp (F) = Tp^ (F). 
To simplify notation we drop the subscripts in the operators. The proof is by 
transfinite induction on a: 



a = 0: Trivial since every hybrid basic formula is mapped to [0, 1] in both op- 
erators. 

Sucessor ordinal a = (3 -\- Let h' = T' and h = By induction 

hypothesis we know that for every F in bfc we have h'{F) = h{F). The 



essential point is that h'{F) C ^ iff 



[1,0]. Therefore, we have 



the body of a rule in P satisfied by h' iff the body of the corresponding 
rule in Php evaluates to [1,0]. Otherwise, the body of the rule in Php has 
truth-value [0,1]. 

Rules of the first kind in the embedding implement the Sp operator because 



F^(/r)(F) = U {m n ^ [sp, (fi) n . . . n Sp, (f^)) 

such that F ^ Sp^ (^Fi^ H ...Hsp^ (^Fk^ G F/^pj 
= U n [1) 0] such that F ^ (^i) n • ■ • n Spf. G Php 

and h (sp^ (^Fi^ n . . . n ^ 

= U where F : /r ^ Fi : A . . . A F^ : is satisfied by h'} 



Rules of the second and third kind extract the maximal interval associated 
with F with respect to connective p. By definition, we know that the maxi- 
mal interval mdp{[a, 6]) is [a, 1] for a conjunctive p-strategy p, or [0, b] if p is a 
disjunctive p-strategy. Therefore the rules of the second and third kind imple- 
ment jj {mdp{p)\ < p,,p >G M} for both cases lb) and 2 of Definition 18. Fi- 
nally, the remaining rules compute jJ {cp{h'{G), h'{H)) \ G (B H = F}. The 
result immediately follows from Proposition 2. 
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Limit ordinal a other than 0: We have to show that 



n T' f (F) = u f/3 (F) 

/3<a 0<a. 



Suppose for every (3 < a we have T' (F) ^ 0 . This means that T' 

(F) = (F). The result then follows again from Proposition 2. 

If for some (3 it is the case that T' {F) = 0 this means T' (F) = 0 . By 
induction hypothesis, (F) = [o/ 3 , 6 / 3 ] with 0/3 > bjs- Let (F) = 

[aa,bo\- We conclude [o/ 3 , 6 / 3 ] < [aa,ba] by monotonicity of T'*, i.e. Oq > ajs 
and bjs > ba- Obviously, Uq, > b^ and the theorem holds. 



□ 



By Theorem 3 we conclude immediately that IfpT^ is the least fixpoint 
of Dekhtyar and Subrahmanian’s Tp operator, and the embedding is proved. 
The convergence of the process is guaranteed both by the properties of the Tp 
operator and the fixpoint results for residuated logic programs. We now return 
to Example 1 to illustrate the embedding. For simplicity, we ignore the rules 
generated in the fourth step for annotated disjunctions since they will not be 
required. 



Example 3. The first two rules will be encoded as follows: 



[0.4, 0.9] /; 

price-drop ^ S[o.85.i] 



ch-sells-stock A^gc ch-retires 



[ 0 . 05 , 0 . 2 ] /: 

price-drop ^ S[i_i] (ch-sells-stock Apcc ch-retires 

Additionally, the following two rules will be introduced by the fourth step in the 
transformation : 



ch-sells-stock A^gc ch-retires 
ch-sells-stock Apcc ch-retires 



[ 1 . 0 ] 



[ 1 . 0 ] 



^igc 



^pcc 



^ch-sells-stock, ch-retires^ 
^ch-sells-stock, ch-retires 

In the first situation, the two facts will be translated to 

[1.1] 

ch-sells-stock ^ [ 1 , 0 ] 

[0.9,1] 

ch-retires ^ [ 1 , 0 ] 



In the least fixpoint of T*' the literals ch-sells-stock and ch-retires have truth- 
value [1, 1] and [0.9, 1], respectively. From this we obtain for the literals repre- 
senting hybrid basic formulas ch-sells-stock Aigc ch-retires and ch-sells-stock Apcc 
ch-retires the same truth- value of [0.9, 1]. Finally, we obtain the interval [0.4, 0.9] 
by application of the first rule. 
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The fact (ch-sells-stock Aigc ch-retires):[l,l] will be encoded instead as fol- 
lows, by application of the first and second rules: 

[M] 

ch-sells-stock Aigc ch-retires ^ [1,0] 

[ 1 . 1 ] 

ch-sells-stock ^ [1,0] 

[ 1 . 1 ] 

ch-retires ^ [1,0] 

From the above facts we conclude that ch-sells-stock Apcc ch-retires gets truth- 
value [1, 1], and by application of the rules for price-drop we obtain for this literal 
the assignment [0.4, 0.2], and as expected [0.4, 0.2] = 0. 

We conclude by remarking that the substitution of F : ^ by instead 

of by Sg (F) in the transformed program is of the essence. Otherwise, we could 
get different semantics when some literal is mapped to 0. However, it is not 
clear what is the better semantics in that case, and further work is necessary. 
We illustrate the distinction in the next example: 

Example 4- Consider the hp-program: 

a: [0.5, 0.7]^ a: [0.8, 0.9]^ 6 : [1, 1] ^ a : [0.9, 0.95] 

According to the transformation of Definition 22 we have: 

[ 0 . 5 , 0 . 7 ] [ 0 . 8 , 0 . 9 ] [ 1 , 1 ] 

a ^ [1,0] a [1,0] ^ ^ ^[o. 9 , 0 . 95 ] 

In the model of the program a is mapped to [0.8, 0.7] and b to [1, 1]. Now, if we 

[ 1 . 1 ] 

translate the rule for 6 as 6 ^ S[o.g,o. 95 ] (®), literal a is still mapped to [0.8, 0.7]. 
However, the body of the rule for b has truth-value [0, 1], and b also has this 
value, since [1, 1] □ [0, 1] = [0, 1]. 

5 Conclusions and Further Work 

The major contribution of this paper is the generality of our setting, both at 
the language and the semantic level. We presented an algebraic characterization 
of Residuated Logic Programs. Program rules have arbitrary monotonic body 
functions and our semantical structures are residuated lattices, where a general- 
ized form of Modus Ponens Rule is valid. After having defined an implication (or 
residuum operator) and the associated multiplication (t-norm in the fuzzy logic 
setting) we obtain a logic programming semantics with corresponding model and 
fixpoint theory. 

The embedding of hybrid probabilistic logic programs into residuated logic 
programs relies on a generalization of the complete lattice of closed intervals in 
[0, 1]. The extra truth- values capture invalid probability interval assignments, not 
used in [4] . The program transformation capturing the hp-semantics is a direct 
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translation of the fixpoint conditions on a logic program. This aspect illustrates 
the generality and potential of our approach. Besides hp-programs we have shown 
that Generalized Annotated Logic Programs, Fuzzy Logic Programming, and 
Possibilistic Logic Programming are all captured by Residuated Logic Programs. 
These results could not be included for lack of space. 

Our work paves the way to combine and integrate several forms of reasoning 
into a single framework, namely fuzzy, probabilistic, uncertain, and paracon- 
sistent. We have also defined another class of logic programs, extending the 
Residuated one, where rule bodies can be anti-monotonic functions, with Well- 
Founded and Stable Model like semantics. This brings together non- monotonic 
and incomplete forms of reasoning to those listed before. It will be the subject 
of a forthcoming paper. 
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Abstract. A framework to deal with spatial patterns at the qualitative 
level of mereotopology is proposed. The main contribution is to provide 
formal tools for issues of model equivalence and model similarity. The 
framework uses a multi-modal language S4„ interpreted on topological 
spaces (rather than Kripke semantics) to describe the spatial patterns. 
Model theoretic notions such as topological bisimulations and topological 
model comparison games are introduced to define a distance on the space 
of all topological models for the language S4u. In the process, a new take 
on mereotopology is given, prompting for a comparison with prominent 
systems, such as RCC. 

Keywords: qualitative spatial reasoning, RCC, mereotopology, model 

comparison games 



1 Introduction 

There are various ways to take space qualitatively. Topology, orientation or dis- 
tance have been investigated in a non-quantitative manner. The literature espe- 
cially is abundant in mereotopological theories, i.e. theories of parthood P and 
connection C. Even though the two primitives can be axiomatized independently, 
the definition of part in terms of connection suffices for AI applications. Usually, 
some fragment of topology is axiomatized and set inclusion is used to interpret 
parthood (see the first four chapters of [9] for a complete overview). 

Most of the efforts in mereotopology have gone into the axiomatization of the 
specific theories, disregarding important model theoretic questions. Issues such 
as model equivalence are seldom (if ever) addressed. Seeing an old friend from 
high-school yields an immediate comparison with the image one had from the 
school days. Most often, one immediately notices how many aesthetic features 
have changed. Recognizing a place as one already visited involves comparing the 
present sensory input against memories of the past sensory inputs. “Are these 
trees the same as I saw six hours ago, or are they arranged differently?” An image 
retrieval system seldom yields an exact match, more often it yields a series of 
‘close’ matches. In computer vision, object occlusion cannot be disregarded. One 
‘sees’ a number of features of an object and compares them with other sets of 
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features to perform object recognition. Vision is not a matter of precise matching, 
it is more closely related to similarity. The core of the problem lies in the precise 
definition of ‘close’ match, thus the question shall be: How similar are two spatial 
patterns ? 

In this paper, a general framework for mereotopology is presented, providing 
a language that subsumes many of the previously proposed ones, and then model 
theoretic questions are addressed. Not only a notion of model equivalence is 
provided, but also a precise definition of distance between models. 

2 A General Framework for Mereotopology 

2.1 The Language S4u 

The proposed framework takes the beaten road of mereotopology by extending 
topology with a mereological theory based on the interpretation of set inclusion 
as parthood. Hence, a brief recall here of the basic topological definitions is in 
order. 

A topological space is a couple {X,0), where X is a set and O C V{X) such 
that: 0 € O, X G O, O is closed under arbitrary union, O is closed under finite 
intersection. An element of O is called an open. A subset A of V is called closed 
if V — A is open. The interior of a set A C V is the union of all open sets 
contained in A. The closure of a set A C V is the intersection of all closed sets 
containing A. 

To capture a considerable fragment of topological notions a multi-modal 
language S4„ interpreted on topological spaces (a la Tarski [17]) is used. A 
topological model M = {X, O, v) is a topological space {X, O) equipped with a 
valuation function v ■. P ^ V{X), where P is the set of proposition letters of 
the language. 

The definition and interpretation of S4„ follows that given in [2]. In that 
paper though, emphasis is given to the topological expressivity of the language 
rather than the mereotopological implications. Every formula of S4„ represents 
a region. Two modalities are available, □(p to be interpreted as “interior of the 
region (/?”, and Utp to he interpreted as “it is the case everywhere that :p.” The 
truth definition can now be given. Consider a topological model M = {X, O, v) 
and a point x G X\ 

M,x\= p iff a; e i^(p)(with p G P) 

M,x \= iff not M,x \= (f 

M, X \= ip ^ Ip iff not M, x\= ip or M, x \= 'tp 

M,x \= Uip iff 3o G O ■. X G o 

tjy Go-. M,y\^ip 
iff tjy G X : M,y \= ip 



M,x\= Uip 
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Since □ is interpreted as interior and O (defined dually as Otp <-> for 

all Lp) as closure, it is not a surprise that these modalities obey the following 
axioms^, [17]: 



T 

□ 


(T) 


□A ^ nnA 


(4) 


□T 


(N) 


□Aa DR e-> D(AAR) 


(R) 



(4) is idempotence, while (N) and (R) are immediately identifiable in the def- 
inition of topological space. For the universal — existential modalities U and E 
(defined dually: Elp -^U^ip) the axioms are those of S5: 

U{ip ^ Ip) (Uip ^ Uip) 

U(p ^ (p 
Uip UUip 
If UE(p 

In addition, the following ‘connecting’ principle is part of the axioms: 

<}ip Eip 

The language S4„ is thus a multi-modal S4*S5 logic interpreted on topological 
spaces. Extending S4 with universal and existential operators to get rid of its 
intrinsic ‘locality’ is a known technique used in modal logic, [12]. In the spa- 
tial context, similar settings have been used initially in [7] to encode decidable 
fragments of the region connection calculus RCC (the fundamental and most 
widely used qualitative spatial reasoning calculi in the field of AI, [14]), then 
by [15] to identify maximal tractable fragments of RCC and, recently, by [16]. 
Even though the logical technique is similar to that of [7,15], there are two im- 
portant differences. First, in the proposed use of S4„ there is no commitment to 
a specific definition of connection (as RCC does by forcing the intersection of 
two regions to be non-empty). Second, the stress is on model equivalence and 
model comparison issues, not only spatial representation. On the other hand, 
there is no treatment here of consistency checking problems, leaving them for 
future investigation. 

2.2 Expressivity 

The language S4„ is perfectly suited to express mereotopological concepts. Part- 
hood P: a region A is part of another region B if it is the case everywhere that 
A implies B: 



(K) 

(T) 

(4) 

(B) 



P(A,B) := U{A B) 



^ The axiomatization of □ given is known as S4. Usually thought S4’s axiomatization 
is given replacing axioms (N) and (R) by (K), see [7]. 
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This captures exactly the set-inclusion relation of the models. As for connection 
C, two regions A and B are connected if there exists a point where both A and 
B are true: 



C(A,B) := E{AAB) 

From here it is immediate to define all the usual mereotopological predicates 
such as proper part, tangential part, overlap, external connection, and so on. 
Notice that the choice made in defining P and C is arbitrary. So, why not take a 
more restrictive definition of parthood? Say, A is part of B whenever the closure 
of A is contained in the interior of B1 

P(A,B) := U{OA UB) 

As this formula shows, S4„ is expressive enough to capture also this definition 
of parthood. In [10], the logical space of mereotopological theories is system- 
atized. Based on the intended interpretation of the connection predicate C, and 
the consequent interpretation of P (and fusion operation), a type is assigned to 
mereotopological theories. More precisely, a type is a triple r = (i,j,k), where 
the first i refers to the adopted definition of Ci, j to that of Pj and k to the 
sort of fusion. The index i, referring to the connection predicate C, accounts for 
the different definition of connection at the topological level. Using S4„ one can 
repeat here the three types of connection: 

Ci(A,B):= E{AAB) 

C2(A, B):= E{A a OB) V E{OA A B) 

C3(A,B):= E{0AA0B) 

Looking at previous mereotopological literature, one remarks that RCC uses a C 3 
definition, while the system proposed in [4] uses a Ci. Similarly to connectedness, 
one can distinguish the various types of parthood, again in terms of S4„: 

Pi(A,B):=C/(A^R) 

P2(A,B):= U{A OB) 

P3(A,B):= U{0A OB) 

In [10], the definitions of the Ci are given directly in terms of topology, and the 
definitions of Pj in terms of a first order language with the addition of a predicate 
Ci. Finally, a general fusion <j)^ is defined in terms of a first order language with 
a Ci predicate. Fusion operations are like algebraic operations on regions, such 
as adding two regions (product), or subtracting two regions. One cannot repeat 
the general definition given in [10] at the S4„ level. Though, one can show that 
various instances of fusion operations are expressible in S4„. For example, the 
product Axk B: 

A XiB:= Aar 

A X 2 B:= {OA AB)y {AA OB) 

A XsB:= (OAAOB) 
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The above discussion has shown that S4„ is a general language for mereotopology. 
All the different types r = {i,j,k) of mereotopological theories are expressible 
within S4„. 




Fig. 1. The positioning of S4„ and RCC with respect to well-known logics. 



Before diving into the similarity results of this paper a remark is in order. 
The language S4„ is a multi-modal language with nice computational properties. 
It is complete with respect to topological models, it is decidable, it has the finite 
model property (see [3] for the proofs of these facts) . It captures a large and “well- 
behaved” fragment of mereotopology, though it is not a first-order language. In 
other words, it is not possible to quantify over regions. A comparison with the 
best-known RCC is in order. 

Comparison with RCC RCC is a first order language with a distinguished 
connection predicate C3. The driving idea behind this qualitative theory of space 
is that regions of space are primitive objects and connection is the basic predi- 
cate. This reflects in the main difference between RCC and the proposed system, 
which instead builds on traditional point-based topology. 

RCC and S4u capture different portions of mereotopology. 

To show this, two formulas are given: an RCC formula which is not expressible 
in S4„ and, vice-versa, one expressible in S4„, but not in RCC. The situation is 
depicted in Figure 1. In RCC, one can write: 

yA3B:P{A,B) (a) 

meaning that every region is part of another one (think of the entire space) . On 
the other hand, one can write a S4„ formula such as: 

^E{pA<>0^p) (/ 3 ) 

which expresses the regularity of the region p. It is easy to see that a is not 
expressible in S4„ and that (d is not in RCC. 
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This fact may though be misleading. It is not the motivations, nor the core 
philosophical intuitions that draw the line between RCC and S4„. Rather, it 
is the logical apparatus which makes the difference. To boost the similarities, 
next it is shown how the main predicates of RCC can be expressed within S4„. 
Consider the case of RCC8: 



RCC8 


S4„ 


Interpretation 


DC(A,B) 


-.B(AA B) 


A is Disconnected from B 


EC(A,B) 


E{0A/\0B)A 
^B(DA A DB) 


A and B are Externally Connected 


P0(A,B) 


E{A A B) A E{A A -.B)A 
E{-^AaB) 


A and B Properly Overlap 


TPP(A, B) 


U{A B)A 

E{OA A OB A O-iA A O-iB) 


A is a Tangential Proper Part of B 


NTPP(A, B) 


U{OA^ OB) 


A is a Non Tangential Proper Part of B 


TPPi(A,B) 


U{B A)A 

E{OB A OA A O-iB A O-iA) 


The inverse of the TIP predicate 


NTPPi(A, B) 


U{OB OA) 


The inverse of the HTTP predicate 


EQ(A,B) 


U{A ^ B) 


A and B are EQual 



Indeed one can define the same predicates as RCC8, but as remarked before the 
nature of the approach is quite different. Take for instance the non tangential 
part predicate. In RCC it is defined by means of the non existence of a third 
entity C: 

NTTP(A, B) iff P(A, B) A ^P(R, A) A ^3C[EC(C, A) A EC(C, B)] 

On the other hand, in S4„ it is simply a matter of topological operations. As 
in the previous table, for NTTP(A, R) it is sufficient to take the interior of the 
containing region DR, the closure of the contained region OA and check if all 
points that satisfy the latter OA also satisfy the former DR. 

The RCC and S4„ are even more similar if one takes the perspective of looking 
at RCC’s modal decidable encoding of Bennett, [7]. Bennett’s approach is to start 
from Tarski’s original interpretation of modal logic in terms of topological spaces 
(Tarski proves S4 to be the complete logic of all topological spaces) and then to 
increase the expressive power of the language by means of a universal modality. 
The positive side effect is that the languages obtained in this manner usually 
maintain nice computational properties. The road to S4„ has followed the same 
path and was inspired by Bennett’s original work. 
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Here is the most important difference of the two approaches: the motivation 
for the work of Bennett comes from RCC, the one for the proposed framework 
from topology. S4„ keeps a general topological view on spatial reasoning, it gives 
means to express more of the topological intricacy of the regions in comparison 
with RCC. For example regularity is not enforced by axioms (like in RCC), but it 
is expressible directly by a S4„ formula (/?). More on the ‘topological expressive 
power’ of S4 and its universal extension can be found in [2]. 



3 When Are Two Spatial Patterns the Same? 

One is now ready to address questions such as: When are two spatial patterns 
the same? or When is a pattern a sub-pattern of another one? More formally, 
one wants to define a notion of equivalence adequate for S4„ and the topological 
models. In first-order logic the notion of ‘partial isomorphism’ is the building 
block of model equivalence. Since S4„ is multi-modal language, one resorts to 
bisimulation, which is the modal analogue of partial isomorphism. Bisimulations 
compare models in a structured sense, ‘just enough’ to ensure the truth of the 
same modal formulas [8,13]. 

Definition 1 (Topological bisimulation). Given two topological models 
{X, O, v), {X', O' , v'), a total topological bisimulation is a non-empty relation ^ 
C X X X' defined for all x G X and for all x' G X' such that if a: ^ a;': 

(base): x G v{p) iff x' G v'{p) (for any proposition letter p) 

(forth condition) : li x G o G O then 

3o' G O' : x' G o' and Vy' G o' : 3y G o : y ^ y' 

(back condition) : if x' G o' G O' then 

3o G O \ X G o and \/y G o : 3y' G o' : y ^ y' 

If only conditions (i) and (ii) hold, the second model simulates the first one. 

The notion of bisimulation is used to answer questions of ‘sameness’ of models, 
while simulation will serve the purpose of identifying sub-patterns. Though, one 
must show that the above definition is adequate with respect to the mereotopo- 
logical framework provided in this paper. 

Theorem 1. Let M = (X,0,iy), M' = {X' ^O' ,v') be two models, x G X, and 
x' G X' bisimilar points. Then, for any modal formula (p in S)u, M,x \= ifi ijf 
M',x' h T- 



Theorem 2. Let M = {X,0,v), M' = {X' ,0' ,v') be two models with finite 
O, O' , X G X , and x' G X' such that for every (p in S)u, M, x\= ip iff M', x' ^ tp. 
Then there exists a total bisimulation between M and M' connecting x and x' . 
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In words, extended modal formulas are invariant under total bisimulations, while 
finite modally equivalent models are totally bisimilar. The proofs are straight- 
forward extensions of those of Theorem 1 and Theorem 2 in [2] , respectively. In 
the case of Theorem 1, the inductive step must be extended also to consider the 
universal and existential modalities; while for Theorem 2, one needs to add an 
universal quantification over all points of the two equivalent models. One may 
notice, that in Theorem 2 a finiteness restriction is posed on the open sets. This 
will not surprise the modal logician, since the same kind of restriction holds for 
Kripke semantics and does not affect the proposed use for bisimulations in the 
mereotopological framework. 



4 How Different Are Two Spatial Patterns? 

If topological bisimulation is satisfactory from the formal point of view, one 
needs more to address qualitative spatial reasoning problems and computer vi- 
sion issues. If two models are not bisimilar, or one does not simulate the other, 
one must be able to quantify the difference between the two models. Further- 
more, this difference should behave in a coherent manner across the class of all 
models. Informally, one needs to answer questions like: How different are two 
spatial patterns? 

To this end, the game theoretic definition of topo-games as in [2] is recalled, 
and the prove of the main result of this paper follows, namely the fact that 
topo-games induce a distance on the space of all topological models for S4„. 
First, the definition and the theorem that ties together the topo-games, S4„ and 
topological models is given. 

Definition 2 (Topo-game) . Consider two topological models {X,0,iy), {X', 
O' , v') and a natural number n. A topo-game of length n, notation TG{X, X', n), 
consists of n rounds between two players. Spoiler and Duplicator, who move 
alternatively. Spoiler is granted the first move and always the choice of which 
type of round to engage, either global or local. The two sorts of rounds are 
defined as follows: 

~ global 

(i) Spoiler chooses a model Xg and picks a point Xg anywhere in Xg 

(ii) Duplicator chooses a point Xd anywhere in the other model Xd 

— local 

(i) Spoiler chooses a model Xg and an open Og containing the current point 
Xg of that model 

(ii) Duplicator chooses an open Od in the other model Xd containing the 
current point Xd of that model 

(iii) Spoiler picks a point Xd in Duplicator’s open Od in the Xd model 

(iv) Duplicator replies by picking a point Xg in Spoiler’s open Og in Xg 
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The points Xg and Xd become the new current points. A game always starts by 
a global round. By this succession of actions, two sequences are built. The form 
after n rounds is: 



{xi,X2,X^, . . ,,Xn} 



Wi,X2,X3,...,x'J 

After n rounds, if Xi and x[ (with i G [l,n]) satisfy the same propositional 
atoms. Duplicator wins, otherwise. Spoiler wins. A winning strategy (w.s.) for 
Duplicator is a function from any sequence of moves by Spoiler to appropriate 
responses which always end in a win for him. Spoiler’s winning strategies are 
defined dually. 

The multi-modal rank of a S4„ formula is the maximum number of nested modal 
operators appearing in it (i.e. □, O, U and E modalities). The following adequacy 
of the games with respect to the mereotopological language holds. 

Theorem 3 (Adequacy). Duplicator has a winning strategy for n rounds in 
TG{X, X' ,n) iff X and X' satisfy the same formulas of multi-modal rank at 
most n. 

The reader is referred to [2] for a proof, various examples of plays and a discussion 
of winning strategies. 

The interesting result is that of having a game theoretic tool to compare 
topological models. Given any two models, they can be played upon. If Spoiler 
has a winning strategy in a certain number of rounds, then the two models are 
different up to a certain degree. The degree is exactly the minimal number of 
rounds needed by Spoiler to win. On the other hand, one knows (see [2]) that if 
Spoiler has no w.s. in any number of rounds, and therefore Duplicator has in all 
games, including the infinite round game, then the two models are bisimilar. 

A way of comparing any two given models is not of great use by itself. It 
is essential instead to have some kind of measure. It turns out that topo-games 
can be used to define a distance measure. 

Definition 3 (isosceles topo-distance). Consider the space of all topological 
models T. Spoiler’s shortest possible win is the function spw : TxT ^ iVU{oo}, 
defined as: 



spw{Xi,X2) 



' n if Spoiler has a winning 

strategy in TG{Xi,X 2 ,n), 
but not in TG{Xi, X 2 , n — 1) 

00 if Spoiler does not have a 
winning strategy in 
TG(Ai,A2,oo) 




82 



Marco Aiello 






tmd= _L : 
spw 



, tmd= _L : 
\ spw 



0 











e(9 A-'^D'p) 



Fig. 2. On the left, three models and their relative distance. On the right, the 
distinguishing formulas. 



The isosceles topo-model distance (topo- distance, for short j between X\ and X 2 
is the function tmd : T x T ^ [0, 1] defined as: 

tmd{Xl,X2) = .y y , 

spw[Xi,X2) 

The distance was named ‘isosceles’ since it satisfies the triangular property in 
a peculiar manner. Given three models, two of the distances among them (two 
sides of the triangle) are always the same and the remaining distance (the other 
side of the triangle) is smaller or equal. On the left of Figure 2, three models are 
displayed: a spoon, a fork and a plate. Think these cutlery objects as subsets of 
a dense space, such as the real plane, which evaluate to (j), while the background 
of the items evaluates to ^cj). The isosceles topo-distance is displayed on the left 
next to the arrow connecting two models. For instance, the distance between 
the fork and the spoon is ^ since the minimum number of rounds that Spoiler 
needs to win the game is 2. To see this, consider the formula EOcj), which is true 
on the spoon (there exists an interior point of the region (j) associated with the 
spoon) but not on the fork (which has no interior points). On the right of the 
figure, the formulas used by spoiler to win the three games between the fork, the 
spoon and the plate are shown. Next the proof that tmd is really a distance, in 
particular the triangular property, exemplified in Figure 2, is always satisfied by 
any three topological models. 
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Theorem 4 (isosceles topo-model distance), tmd is a distance measure on 
the space of all topological models. 

Proof, tmd satisfies the three properties of distances; i.e., for all Xi, X2 &T: 

(i) tmd{Xi, X2) > 0 and tmd{Xi, X2) = Q lE X\ = X2 

(ii) tmd{Xi, X2) = tmd{X2, Xi) 

(iii) tmd{Xi, X2) + tmd{X2, X:}) > tmd{Xi, X3) 

As for (i), from the definition of topo-games it follows that the amount of rounds 
that can be played is a positive quantity. Furthermore, the interpretation of 
Xi = X2 is that the spaces Xi, X2 satisfy the same modal formulas. If Spoiler 
does not have a w.s. in lim„^oo ’TG(Ai, A2, n) then Xi, X2 satisfy the same 
modal formulas. Thus, one correctly gets 

tmd{Xi, X2) = lim — = 0. 

n—*oo 71 



Equation (ii) is immediate by noting that, for all Xi, X2, TG{Xi,X2,n) = 
TG{X2,Xi,n). 

As for (iii), the triangular property, consider any three models Xi, X2, X3 and 
the three games playable on them, 

TG(Ai,A2,n), TG(A2,A3,n), TG(Ai,A3,n) (1) 

Two cases are possible. Either Spoiler does not have a winning strategy in all 
three games (1) for any amount of rounds, or he has a winning strategy in at 
least one of them. 

If Spoiler does not have a winning strategy in all the games (1) for any 
number of rounds n, then Duplicator has a winning strategy in all games (1). 
Therefore, the three models satisfy the same modal formulas, spw —>■ 00, and 
tmd —>■ 0. Trivially, the triangular property (iii) is satisfied. 

Suppose Spoiler has a winning strategy in one of the games (1). Via The- 
orem 3 (adequacy), one can shift the reasoning from games to formulas: there 
exists a modal formula 7 of multi-modal rank m such that |= 7 and Xj ^ ^7. 
Without loss of generality, one can think of 7 as being in normal form: 



1 = \/ /\HU{PS4) ( 2 ) 

This last step is granted by the fact that every formula ip of S4„ has an equivalent 
one in normal form whose modal rank is equivalent or smaller to that of 
Let 7* be the formula with minimal multi-modal depth m* with the property: 
Xi ^ 7* and Xj ^ “'7*. Now, the other model Xk either satisfies 7* or its 

^ In the proof, the availability of the normal form is not strictly necessary, but it 
gives gives a better impression of the behavior of the language and it has important 
implementation consequences, [2]. 
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negation. Without loss of generality, Xk ^ 7 * and therefore Xj and Xk are 
distinguished by a formula of depth m* . Suppose Xj and Xk to be distinguished 
by a formula /3 of multi-modal rank h < m*: Xj ^ f3 and Xk ^ ~'/3. By 
the minimality of m*, one has that Xi ^ /?, and hence, Xi and Xk can be 
distinguished at depth h. As this argument is symmetric, it shows that either 

— one model is at distance — from the other two models, which are at distance 

7 “)) or 

— one model is at distance -e from the other two models, which are at distance 

11^ 

r) one from the other. 

It is a simple matter of algebraic manipulation to check that to*, I and h, to* (as 
in the two cases above), always satisfy the triangular inequality. 

The nature of the isosceles topo-distance triggers a question. Why, given three 
spatial models, the distance between two couples of them is always the same? 

First an example, consider a spoon, a chop-stick and a sculpture from Henry 
Moore. It is immediate to distinguish the Moore’s sculpture from the spoon 
and from the chop-stick. The distance between them is high and the same. On 
the other hand, the spoon and the chop-stick look much more similar, thus, 
their distance is much smaller. Mereotopologically, it may even be impossible to 
distinguish them, i.e., the distance may be null. 

In fact one is dealing with models of a qualitative spatial reasoning language 
of mereotopology. Given three models, via the isosceles topo-distance, one can 
easily distinguish the very different patterns. In some sense they are far apart 
as if they were belonging to different equivalence classes. Then, to distinguish 
the remaining two can only be harder, or equivalently, the distance can only be 
smaller. 

5 Concluding Remarks 

In this paper, a new perspective on mereotopology is taken, addressing issues of 
model equivalence and especially of model comparison. Defining a distance that 
encodes the mereotopological difference between spatial models has important 
theoretical and application implications. In addition, the use of model compari- 
son games is novel. Model comparison games have been used only to compare two 
given models, but the issue of setting a distance among a whole class of models 
has not been addressed. The technique employed in Theorem 4 for the language 
S4„ is more general, as it can be used for all Ehrenfeucht-Fraisse style model 
comparison games^ adequate for modal and first-order languages equipped with 
negation. A question interesting per se, but out of the scope of the present pa- 
per, is: which is the class of games (over which languages) for which a notion of 
isosceles distance holds? (E.g. are pebble games suited too?) 

Another question open for further investigation is the computability of the 
topo-distance. First, there is a general issue on how to calculate the distance 

For an introduction to Ehrenfeucht-Fraisse games see, for instance, [11]. 
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for any topological space. One may be pessimistic at a first glance, since the 
definition and the proof of the Theorem 4 are not constructive, but actually 
the proof of the adequacy theorem for topo-games given in [2] is. Furthermore, 
decidability results for the logic S4„ on the usual Kripke semantics (cf. [12]) 
should extend to the topological interpretation. Second, in usual applications 
the topological spaces at hand are much more structured and tractable. For 
example in a typical geographical information system, regions are represented 
as a finite number of open and/or closed polygons. With these structures, it is 
known that finiteness results apply (cf. [3]) and one should be able to compute 
the topo-distance by checking a finite number of points of the topological spaces. 
Currently, an image retrieval system based on spatial relationships where the 
indexing parameter is the topo-distance is being built, [1]. The aim is twofold, 
on the one hand one wants to build a system effectively computing the topo- 
distance, on the other one wants to check with the average user whether and 
how much the topo-distance is an intuitive and meaningful notion. 

Broadening the view, another important issue is that of increasing the ex- 
pressive power of the spatial language, then considering how and if the notion of 
isosceles distance extends. The most useful extensions are those capturing geo- 
metrical properties of regions, e.g. orientation, distance or shape. Again one can 
start by Tarski’s ideas, who fell for the fascinating topic of axiomatizing geome- 
try, [18], but can also follow different paths. For example, staying on the ground 
of modal logics, one can look at languages for incidence geometries. In this ap- 
proach, one distinguishes the sorts of elements that populate space and considers 
the incidence relation between elements of the different sorts (see [6,5,19]). 
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Abstract. In this paper we shall present a translation of the process 
semantics [5] to the event calculus. The aim is to realize a method of 
integrating high-level semantics with logical calculi to reason about con- 
tinuous change. The general translation rules and the soundness and 
completeness theorem of the event calculus with respect to the process 
semantics are main technical results of this paper. 



1 Introduction 

In the real world a vast variety of applications need logical reasoning about phys- 
ical properties in dynamic, continuous systems, e.g., specifying and describing 
physical systems with continuous actions and changes. 

The early research work on this aspect was encouraged to address the prob- 
lem of representing continuous change in a temporal reasoning formalism [1]. 
The standard approach is equidistant, discrete time points, namely to quantify 
the whole scenario into a finite number of points in time at which all system 
parameters are presented as variables. If there were infinitely many points at 
infinitely small distance, this might be sufficient. But, since discretization is al- 
ways finite, a problem arises when an action or event happens in between two 
of these points. 

Some work has been done to extend specific action calculi in order to deal 
with continuous change. The event calculus [7] is one formalism reasoning about 
time and change. It uses general rules to derive that a new property holds as 
the result of the event. In [9, 11, 12, 2], the attempts based on the logical for- 
malisms of the event calculus have been exploited for representing continuous 
change. However, these ideas have not yet been exploited to define a high level 
action semantics serving as basis for a formal justification of such calculi, their 
comparison, and an assessment of the range of their applicability [5]. 

Whereas these previously described formalisms have directly focused on cre- 
ating new or extending already existing specialized logical formalisms, the other 
research direction consists in the development of an appropriate semantics [4, 
10, 14] as the basis for a general theory of action and change, and successfully 
applied to concrete calculi [6, 3, 13]. In [4], the Action Description Language 
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was developed which is based on the concept of single-step actions, and does 
not include the notion of time. In [10], the duration of actions is not fixed, but 
an equidistant discretization of time is assumed and state transitions only occur 
when actions are executed. In [14], it is allowed for user-independent events to 
cause state transitions. Again equidistant discretization is assumed. But these 
formalisms are not suitable for calculi dealing with continuous change. 

In 1996, Herrmann and Thielscher [5] proposed a logic of processes for rea- 
soning about continuous change which allows for varying temporal distances 
between state transitions, and a more general notion of a process is proposed 
as the underlying concept for constructing state descriptions. In the process se- 
mantics, a state transition may cause existing processes to disappear and new 
processes to arise. State transitions are either triggered by the execution of ac- 
tions or by interactions between processes, which both are specified by transition 
laws. 

In this paper we shall present a translation of the process semantics to the 
event calculus. The aim is to realize a method of integrating high-level semantics 
with logical calculi to reason about continuous change. In the following, we first 
review the event calculus and the logic of processes, and then show how the 
process semantics can be represented in the event calculus. On this basis, we 
prove the soundness and completeness of the event calculus with respect to the 
process semantics. 



2 Event Calculus 

The event calculus [7] was developed as a theory for reasoning about time and 
events in a logic programming framework. In the event calculus, the ontological 
primitives are events, which initiate periods during which properties hold. A 
property which has been initiated continues to hold by default until some event 
occurs which terminates it. Time periods are identified by giving their start 
and end times which are named by terms of the form after (e,p) or before{e,p) 
where the first argument is the name of the event which starts or ends the time 
period and the second argument the name of the property itself. A general, 
one-argument predicate hold is used to express that a property p holds for a 
period. 

The occurrence of an event e at time t is denoted by Happens (e,t). The for- 
mula Initiates {e,p) {Terminates{e,p)) means that event e initiates (terminates) 
the property p. 

The reasoning can be formalized by employing a predicate Holds At{p,t) 
where p denotes a property and t a time point: 

HoldsAt{p,t) ^ Holds {after {e,p)), time{e,to), 

In {t, after {e,p)), to < t. 

Holds {after {e,p)) ^ Happens {e,t), Initiates {e,p). 
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It means that a property p holds at the time t if p holds for the period after 
an event e happens at time to, and there exists no such an event which happens 
between to and t and terminates the property p. 

The further domain dependent axioms are needed to define the predicates 
Happens, Initiates and Terminates. 

For example, we express an assertion that the property of possess (Antje, 
Book) holds after the event E{ Tom give the book to Antje) happens. In this case, 
the predicates Initiates and Terminates can be defined as: 

Initiates {e, possess {x,y)) ^ Act{e, Give), Recipient (e,x), Object{e,y). 

Terminates {e, possess {x,y)) ^ Act {e. Give), Donor (e,x), Object{e,y). 

where predicates Act represents the type of event (action). Recipient and Donor 
represent the recipient and the donor of this event (action), and Object the object 
acted be this event (action). 

Thereafter, the assertion HoldsAt {possess {Antje, Book), t) can be derived 
from the predicates defined above for the event description. 

3 Logic of Processes 

In this section, we introduce a formal, high-level semantics proposed by Her- 
rmann and Thielscher [5], for reasoning about continuous processes, their inter- 
action in the course of time, and their manipulation. 

Definition 1. A process scheme is a pair {C, F) where G is a finite, ordered set 
of symbols of size I > 0 and F is a finite set functions f: ^ M. 



Example 1. Let {C,F) be a process scheme describing continuous movement 
of an object on a line as follows: C = {? 0 j i'} and F = {f{lo,v,to,t) = 

lo + V • {t — to)}, where lo denotes the initial location coordinate, v the velocity, 
to and t the initial and the actual time, and we denote I = f{lo,v,to,t) as the 
actual location of the object at time t. 



Definition 2. Let N be a set of symbols (called names). A process is a f-tuple 
{n, T, to, p) where 

1. n€ N; 

2. T = {C, F) is a process scheme where G is of size m; 

3. to G IR; and 

4- P = {Ph ■ ■ ■ iPm) G kR™ is an m-dimensional vector over M. 
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Example 2. Let Tmove denote the example scheme from above then 

{TrainA,Tmove, 1 :00pm, {Omi, 25mph)) 

{ TrainB, Tmove > 1:30pm, {80mi, -20mph)) 

are two processes describing two trains moving toward each other with different 
speeds at different starting times. 



Definition 3. A situation is a pair (S,ts) where S is a set of processes and tg 
is a time-point which denotes the time when S started. 



Definition 4. An event is a triple (Pi,t, P 2 ) where Pi {the precondition) and 
P 2 {the effect) are finite sets of processes and t € M is the time at which the 
event is expected to occur. 



Definition 5. An event {P\,t, P 2 ) is potentially applicable in a situation {S, tg) 
iff Pi ^ S and t > tg. If e is a set of events then an event (Pi,t, P 2 ) G £ 
is applicable to {S,tg) iff it is potentially applicable and for each potentially 
applicable {P{,t',Pf} G e we have t < t' . 



Example 3. Let S denote the two processes of Example 2. Further, let tg = 
3:00pm, then the following event, which describes an inelastic collision which is 
interpreted as a coupling of trains, is applicable to (S, tg)\ 

{Pi = {{TrainA, Tmove, 1:00pm, {Omi, 25mph)) , 

{TrainB, Tmove, 1:30pm, {80mi,-20mph))} 

t = 3:00pm 

P 2 = {{TrainA, Tmove, 3:00pm, {50mi, 5mph)), 

{TrainB, Tmove, 3:00pm, {50mi, 5mph))}) 

In fact, concrete events are instances of general transition laws which contain 
variables and constraints to guide the process of instantiation, and the event’s 
time is usually determined by the instances of other variables. We can describe 
the transition law for inelastic collisions of two continuously moving objects as 
follows. 

{Pi = {{Na, T move, T ao,{1^ AO, Va)), 

{Nb, Tmove, Tbo, {^bo, he))} 

t = T (Tl) 

P2 = {{NA,TmOVe,P,{i^new,yA-\-yB)), 

{Nb , Tmove ,T,{X new 1 + l^s))}) 
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where it is required that Na ^ Nb, Va — Vb 0, and xa = xb = Xnew at time 
T. XA and xb represent the actual location of Train A and TrainB respectively 
when the collision occurs. Suppose that the two movement differentials are xa = 
Xao + Va ■ {T — Tao) and xb = Xbo + Vb • (T — Tbo); then the result is: 

y = X^o-Xbo-Va-T^o+Vb-Tbo ^ x^^en, = X AO + Va ' {T - Tao) (T2) 



Definition 6. Let e he a set of events and (SAs) a situation, then the successor 
situation <P{{S,ts)) is defined as follows. 

1. If no applicable event exists in e then <P{{S,ts)) = (S', oo); 

2. if {Pi,t, P 2 ) € s is the only applicable event then <L{{S,ts)) = (S',ts) where 

S' = (S \ Pi) U P 2 and tg/ = t] 

3. Otherwise <P{{S,ts)) is undefined, i.e., events here are not allowed to occur 
simultaneously. 



Definition 7. An observation is an expression of the form [t] oc (n) = r where 

1. t € IR is the time of the observation; 

2. oc is either a symbol in C or the name of a function in F for some process 
scheme (C,F); 

3. n is a symbol denoting a process name; and 

4 . r € M is the observed value. 

Given an initial situation and a set of events, such an observation is true iff 
the following holds. Let S be the collection of processes describing the system 
at time t, then S contains a process (n, (C, F),to, {r\, . . . ,rn,to)) such that 

1. either G = (co, . . . , Cfc_i, oc, Cfc+i, . . . , c^-i) and rj, = r; 

2. or oc€ F and oc (ri, . . . ,r„,toG) = n. 



Example 4 - The observation [2:15pm] Z(TromP) = 65mz is true in Example 3, 
while the observation [3:l5pm\l{TrainB) = 45mz is not true since the latter does 
not take into account the train collision. 



Definition 8. A model for a set of observations F {under given sets of names 
N and events S ) is a system development {So, to), d>{{So,to)), d>'^{{So,to)), . . . 
which satisfies all elements ofF. Such a set F entails an {additional) observation 
iff Ip is true in all models ofF. 

All definitions concerning successor situations, developments, and observa- 
tions carry over to the case where a set of actions, which are to be executed 
(external events), and interactions between processes (internal events) are given. 
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4 Translation of the Process Semantics to the Event 
Calculns 



In order to represent the process semantics in the event calculus, we here adopt 
the formalisms of the event calculus of Kowalski [7] and a variant presented by 
Shanahan [12]. 

Let D = {P, Eproc) be a domain description in the process semantics. D 
consists of a set of processes P and a sequence of events Eproc- The correspond- 
ing formalism of the event calculus uses variables of two sorts: event variables 
ei,C 2 , . . . , time variables . • • , and a process is represented as a relation 

P{n, R, C) where n denotes the process name, and R and C the sets of dynamic 
and static parameters respectively defined in the process semantics. The rela- 
tion Q{n, E, R, C) expresses the property of the process, which holds true during 
the period of continuous change. F denotes a finite set of functions describing 
the relationship between the dynamic and static parameters. In fact, the con- 
tent of the process scheme in the process semantics is specified by the function 
Q{n, E, R,C). There are also some predicate symbols whose meaning will be 
clear from their use in the rules below. 

Processes and events defined in the process semantics can be formalized as 
the following general rules by the event calculus. 

Holds At {P{n, R, C),t) ^ 

Holds {after {e, Q(n, F, R, C))), time (e, to), 

In{t, after {e,Q{n, F, R,C))), to<t, (Gl) 

State{t,s), HoldsIn{P{n, R,C), s), 

Continuous Property {Q{n, F, R, C), to, P{n, R, C), t). 



~^HoldsAt{P{n, R,C),t) ^ State{t,s), ^HoldsIn{P{n, R,C), s). 

Holds {after {e,Q{n, F, R, C))) ^ 

EventTrigger {e,t) , Initiates{e, Q{n, F, R, C)). 

EventTrigger{e,t) ^ Happens {e,t). 

EventTrigger {e,t) ^ ImplicitHappens {e,t). 

In {t, p) ^ Start {p,e\), End{p,e 2 ), Time{ei,ti), 

Time{c 2 , t 2 ),t\ <t <t 2 - 

Continuous Property {Q{n, F, R, C), to, P{n, R, C),t) <— 

R = F{C,t,to). 



(G2) 

(G3) 

(G4) 

(G5) 

(G6) 

(G7) 



In (Gl) the predicate ContinuousProperty in the event calculus treats con- 
tinuous change in correspondence with the process semantics. It means that 
property P{n, R, C) holds during the period of continuous change Q {n, F, R, 
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C) which starts at time to and varies with time t. The rule (G7) specifies the 
premise condition required for the predicate ContinuousProperty to hold. 

In addition, there are two cases for the occurrence of an event: an event is 
triggered by an external action and initial condition, or implicitly by the tran- 
sition between processes (defined in the process semantics). In (G4) and (G5), 
the trigger of an event is formalized by the predicates EventTrigger, Happens, 
ImplicitHappens. In (G6), it is represented by the predicate In{t,p) that t is a 
time point in the time period p. 

An event in the process semantics is defined as a triple {P,t,P'). P and 
P' are finite sets of processes. The event is expected to occur at time t. The 
result of occurrence of the event is that each process in P is transformed into 
the corresponding new process in P'. It is assumed that the set P (resp. P') 
includes k processes P = {pi, . . . ,pk) (resp. P' = {p[, . . . ,p']^)). The transition of 
processes from P into P' happens by the event implicitly. For that we can define 
the event of the process semantics in the event calculus as follows. 



ImplicitHappens (e, t) <— 

Start {after {e, Q{ui, Fi,Ri, Ci)),e), 

End {after {e',Q{n{,Fl,R{,Cl)),e), e' < e, 

Constraint Relation {Ri,R{, . . . , Rk, R'^ft). 

Constraint Relation {Ri,Rft . . . , Rk, R'kft) 

g{Fi{Ci,t), F{{C[,t), . . . , Fk{Ck,t), Fl,{C{,,t)) = Constant. 



(G8) 



(G9) 



Here the predicate Constraint Relation is conditioned by a constraint equa- 
tion. The dynamic and static parameters (i?i, . . . , Rk), {C\, . . . , Ck) of the pro- 
cesses in the sets P and {R{, . . . , R'ft), {C[,...,C'ft) in the sets P' meet the 
equation at a specific time t. With this equation we can calculate the value of 
the time at which the event occurs. 

To avoid the concurrent events which can not be represented in the process 
semantics, we give the following rule. 



e = e' <— Happens (e, t). Happens {e' ,t), 

after {e, Q{n, F, R,C)) = after {e' ,Q{n, F, R, C)) 



(GIO) 



In order to formalize properties of processes and continuous change in the 
event calculus, we furthermore introduce the following basic axioms (ESI) - 
(ES6) partly based on the Shanahan’s work [12]. In the Shanahan’s variant 
version of event calculus, a many-sorted language of the first-order predicate 
calculus with equality is used, including variables for time points {t, ti, t 2 , ■ ■ .), 
properties {p, pi, p 2 , q, qi, q 2 , ■■■), states (s, si, S 2 , . . .), truth values {v, v\, 
V 2 , ...), and truth elements (/, /i, / 2 , ...). The domain of truth values has 
two members, denoted by the constants True and False. A pair {p,v) is a truth 
element. A state is represented as a set of truth elements. 



Si = S2 ^ (V/) [/ G Si ^ / e S2]. 

(Vsi, /i)(3s2V/2) [/2 G S2 ^ [/2 G Si V /2 = /ijj. 



(ESI) 

(ES2) 
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(3s) (V/) h/ e s], (ES3) 

Holdsin {p, s) ^ [(p, True) € s A ^Abstate (s)]. (ES4) 

-^Holdsln {p, s) ^ [{p, False) € s A ^Ahstate (s)]. (ES5) 

State {t, s) ^ 

(Ve,p) [[(p, True) G s ^ {Initiates {e,p) A Happens {e,t))] A (ES6) 

[(p, False) G s ^ {Terminates {e,p) A Happens {e,t))]]. 



In the rest of this paper, the set of axioms (ESI) - (ES6) and rules (Gl) - 
(GIO) will simply be denoted by ES and G. 

5 An Example 

Gonsider two trains TrainA and TrainB starting at different times and moving 
towards each other with different speed. At the time G a collision happens after 
which they continue to move as a couple with a common speed together. 

In the process semantics we may describe this scenario by the definition of 
processes as follows: 



( TrainA, Tmove , Tao, {Xao, Va)) 
{TrainB, Tmove, Tbo, (Abo, Vb)) 



where Tao and Tbo denote the start times of the trains TrainA, TrainB, Xao, Va 
and Xbo,Vb initial locations and velocities, respectively. Tmove is a symbol 
which denotes the process scheme describing the continuous movement of the 
trains TrainA and TrainB. 

In Section 4 we have defined two relations P{n,R,C) and Q{n,F,R,C) to 
represent the processes in the event calculus. For instance, we instantiate these as 
the relations moving {N , xn, {In, vn, ^n)) and engine{N, T, xn, {In, vn, tN)) 
to formalize the two processes above in the event calculus. Here N represents 
a variable of process name N G { TrainA and TrainB ) . The static parameters 
In, Vn, In G C correspond to the initial location, the velocity and the starting 
time of the train N . The dynamic parameter xn G R corresponds to the actual 
location of the train N , which varies with time. T corresponds to the process 
scheme Tmove of the continuous movement of the trains TrainA and TrainB. 

The description of the two processes can be translated into rules in the event 
calculus: 

HoldsAt {moving {TrainA, X A, {lA,VA,tA)),t) ^ 

Holds {after{e, engine {TrainA, T , xa, {Ia, va, ^a)))), time (e, to), 
In{t,after{e,engine{TrainA,T,XA,{lA,VA,tA)))),to <t, , . 

State{t,s), Holdsin {moving {Train A, X A, {I A, V A, t a)), s), ' 

ContinuousProperty {engine ( TrainA, T , xa, {I a, va, I a)), 
to, moving ( TrainA, xa, {Ia, va, tA)),t). 
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HoldsAt {moving ( TrainB, xb, {Ib, VB,tB)),t) ^ 

Holds {after {e, engine {TrainB, IF,xb, {Ib^vbAb)))), time (e, to)) 
In {t, after{e, engine {TrainB, T,xb, {lB,VB,tB)))),to < 

State {t, s), Holdsin {moving {TrainB, XB,{lB,VB,tB)), s), 
Continuous Property ( engine ( TrainB, lF,XB,{lB,VB,tB)), 
to, moving ( TrainB, xb, {lB,VB,tB)),t). 



ContinuousProperty {engine {N, T , x, {I, v, to)), , 

to,moving{N,x,{l,v,to)),f) ^ X = I + v ■ {t — to)- ' 

By using moving and engine as the general properties we describe a process 
in which a train N moves continuously, t and x denote the actual time and 
location of the train which satisfies the equation x = I + v • {t — to)- I and to 
denote the initial location and time of the occurrence of event e which initiates 
the property engine (engine of train is on) so that the process happens in which 
the train starts to move continuously from the initial location I with velocity v 
till a new event terminates this process. 

In the process semantics, an event is represented as a triple {P, t, P') whereby 
each concrete event is viewed as an instance of the general translation laws. The 
occurrence of an event at time t terminates the former processes P and results 
in new processes P' to occur. We can describe the transition law for inelastic 
collisions of two continuously moving objects by (Tl) and (T2). 

The event for an inelastic collision which is interpreted as a couple of trains 
can be formalized in the event calculus as the following rules. 

ImplicitHappens (e, t) <— 

Start {after {e, engine {TrainA,T,x a, {lnewA,VnewA, t)),e), 

End {after {e\ engine {Train A, F, xa, {hidA, VoidA, toidA)),e), 

Start {after {e, engine {TrainB, F,xb, {lnewB,VnewB,t)),e), (S4) 

End {after {e”, engine {TrainB, F,xb, {loMB,VoidB,toidB)), e), 
e ^ e, e ^ c, Constra%ntRelat%on{lYi^yjA-i^newA-^lnewB-i^newB-i 

loldA ) '^oldA ) loldB j ^oldB ) toldA : toldB A)- 

ConstraintRelatlOn {InewA: '^newAy InewB ) ^newB y loldAy ^oldAy 
loldB y HoldB y toldAy toldB y t) ^ 

loldA l^oldA ' {t toidA^ — loldB l^oldB ' {t toldB) y (^^) 

InewA — InewB — loldA l^oldA ' {t toldA) y 
UnewA — l^newB — l^oldA HoldB- 



We suppose that TrainA (initial location is Omi) starts to move at time 
1:00 pm with the velocity 25mph, while TrainB at time 1:30 pm with the velocity 
-20mph. We describe two events MoveA and MoveB and have the domain- 
dependent formulae as follows. 
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Happens {MoveA, 1:00pm). (HI) 

Happens {MoveB, 1:30pm). (H2) 

In the following, we show that it holds that a collision occurs between TrainA 
and TrainB at 3:00pm and then they move as a couple with a common speed 
together. Here we use circumscription [8] to minimise the extensions of certain 
predicates. 

Let X be the conjunction of the axioms ES, G, S and H without ES6 and 
Gl. CIRCecix] is defined as the conjunction of 

CIRC[x', Happens, Initiates, Terminates] State, HoldsAt] 



with 



CIRC[x', AbState; Happens, Initiates, Terminates, State, HoldsAt]. 

We take the first conjunct of CIRCedx]- Since all occurrence of Happens, 
Initiates, Terminates in y are positive, 

CIRC[x', Happens , Initiates , Terminates] 



is equivalent to 

CIRC[x', Happens] A CIRC [x', Initiates] A CIRC[x', Terminates] 

(See Theorem 3 in the next section). It can be seen that the Happens, Initiates, 
Terminates are true in all of its models, and we have 

Happens (e, t) ^ 

[e = MoveA At = 1:00pm] V [e = MoveB At = 1:30pm] 

Initiates (e,p) ^ 

[e = MoveA Ap = engine {TrainA, T , xa, {Omi, 25mph))] V 
[e = MoveB Ap = engine {TrainB, T,xb, {80mi, -20mph))] 

Since there are no occurrences of State, HoldsAt in y, (1) and (2) are also 
true in all models of CIRCedx]- 

We take the second conjunct of CIRCedx]- The only abnormal combinations 
of true elements are those which include both {p. False) and {p, True) for some 
p. So, in all models of 

CIRC[x', AbState] Happens, Initiates, Terminates] 



( 1 ) 

(2) 



we have 



Abstate{s) ^ {3p) [{p, False) € s A {p, True) G s] 



(3) 
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Since there are no occurrences of State, HoldsAt in Xi allow these predi- 
cates to vary does not affect the outcome of circumscription. So, (3) is also true 
in all models of CIRC ec\x\ - Since (Gl) and (ES6) are chronological, we can show 
that (1), (2) and (3) are also true in all models of CIRC ec[ES A G A S' A iL](See 
Theorem 2 in the next section). 

The combination of (3) with axioms ES, G, S and H ensures that every 
model includes a state in which properties engine and moving hold. 

By the rules (SI) - (S5), we can deduce that an implicit event denoted as etc 
occurs at time 3:00pm, since the condition of the constraint equation in (S4)- 
(S5) is satisfied. It is easy to show from (1), (2), (3) and (S4) - (S5) that in all 
models under circumscription we have 

(3s) [State{30, s) A HoldsIn{moving {TrainAjXA, {50mi, 5mph, 3:00pm)), s) 
AHoldsIn {moving {TrainB,XB, {50mi, 5mph, 3:00pm)), s)] 

Therefore, 

HoldsAt {moving {TrainA,XA,{50mi, 5mph, 3:00pm)), t). 

HoldsAt {moving {TrainB,XB,{50mi, 5mph, 3:00pm)), t). 

where t > 3:00pm. 



6 Soundness and Completeness Theorem 

Definition 9. A marker set is a subset S of R such that, for all T\ in R, the 
set of T 2 in S such that T 2 < T\ is finite. 



Definition 10. A formula ip is chronological in argument k with respect to a 
formula x <md a marker set S if 

(a) it has the form \/x q{x) ^ 4>{x), where qis a predicate whose kth argument 
is a time point and 4>{x) is a formula in which x is free, and 

{b) all occurrences of q in 4>{x) are in conjunctions of the form q{z) A Zk < 
Xk A 9, where x ^ \= if Zk ^ S . 



Theorem 1. Consider only models in which the time points are interpreted as 
reals, and in which < is interpreted accordingly. Let P* and Q* be sets of pred- 
icates such that Q* includes q. Let ip = \/x q{x) ^ <P{x) be a formula which 
is chronological in some argument with respect to a formula x which does not 
mention the predicate q, and a marker set S. Then 

CIRC[xAip-,P*-,Q*] h CIRC[x;P*;Q*]. 

In order to minimize domains and histories, two other properties of circum- 
scription will be useful. 
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Theorem 2. Let A be any formula and 6{x) be any formula in which x is free. 
CIRC[\ A Va; p{x) ^ <5(a;);p] is equivalent to X A\/x p{x) ^ S{x) if X and S(x) 
are formulae containing no occurrences of the predicate p. 



Theorem 3. Let X be any formula and 6(x) be any formula in which x is free. 
If all occurrences of the predicates p\,p 2 , ... ,Pn in a formula X are positive, then 
CIRC[X] P*], where P* = p\,p 2 , . . . ,Pn, is equivalent to 

CIRC[X; pi] A CIRC[X; pz] A . . . A CIRC[X;pn]. 

Here Theorem 1, 2 and 3 are reproduced without proof, but proofs can be 
found in Shanahan’s [12] and Lifschitz’s papers [8], respectively. 

Let T> = {V,S) be consistent domain description for process semantics, 
where 7^ is a set of initial processes and £1 is a set of events. We write V = 
(pi,P 2 , • ■ • ,Pm) and £ = (ci,e 2 , . . . ,e„). 

Let OBS{P,a,ts) denote an observation of the process with name n at time 
ts, where a is a symbol in C or f for some process scheme (C,F) and a = r 
(where r is an observed value) . In the event calculus we describe an observation 
in the following form: HoldsAt{P(n, R,C),ta) A a = r, where a is a variable 
name in i? or C. 

Lemma 1. Let tt denote the defined translation from the process semantics into 
the event calculus and V be a consistent domain description for process seman- 
tics, for any process P if CIRCeclT^P AES AG] \= HoldsAt{P{n, R,C),ts) Aa £ 
{RU C) A a = r, then V entails OBS{P, a, tg) A a = r. 

Proof. Let A denote the conjunction of ttP, ES and G. Suppose that for any 
process P from T>, CIRCec[X] \= HoldsAt{P{n, R,C),ts) Aa G {RU G) Aa = r. 
Then there must exist a state s and it follows that 

(3s) {State {t, s) A HoldsIn{P{n,R,C),s)). 

Since all occurrences of Happens, ImplicitHappens, Initiates and Terminates 
in A are positive, from Theorem 3, we have 

CIRC ec[X; Happens, ImplicitHappens, Initiates, Terminates] 
is equivalent to 

CIRC[X', Happens] A CIRC[X; ImplicitHappens] A CIRC[X; Initiates] A 
CIRC[X; Terminates]. 

Applying Theorem 2 to each conjunct in this formula, it can be seen that Hap- 
pens, ImplicitHappens, Initiates and Terminates are true in all models under 
circumscription . 

Case 1: If HoldsAt{P{n, R,G),ts) A a S (i? U C) A a = r is true, and 
(3e') time{e') < tg A terminates {e' , after{Q{n, F, R, C), e)) is not true, it is clear 
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that in the process semantics any model of V is also the model of the observation 
OBS{P, a, ts), i.e., T> entails OBS{P, a, ts) A a = r. 

Case 2: Assume that there exist a set of events S and for any event e € £, 
time{e) < ts- Since CIRCedM h HoldsAt {P{n, R,C),ts) Aa = r, with the rules 
(Gl)-(GIO) we can deduce that the event e is applicable and occurs at a certain 
time time{e). By applying rules (G8) and (G9) we can further deduce a set of 
processes which are initiated by the event e and meet the rule (Gl) such that 
for one of these processes P{n,R,C), we have HoldsAt {P{n,R,C),ts) A a = r 
holds. It follows that the process P{n, R,C), initiated by the event e, with the 
observed value r is true in all the models of CIRCec[A\- By the Definition 3.8, 
under given events and processes, the observed value a = r is true in all the 
system developments for the observation OBS{P,a,ts). Thus, we have that T> 
entails the observation OBS{P, a, ts) A a = r. 

Theorem 4. [Soundness Theorem] Let T> be a consistent domain description 
for process semantics and tt denote the translation from the process semantics 
into the event calculus, for any process P if ttT) entails irP, then V entails P. 

Proof. By Lemma 1, an observation OBS{P,a,ts) A a = r is entailed by T>, 
if CIRC[ttP a ES a G] ^ ttOBS. Suppose ttV entails irP. Since the observa- 
tion is made during a development of the system being modeled and involved in 
some concrete process at time tg, this observed process holds under the devel- 
opment of the system (given the set of initial processes and the set of events), 
if HoldsAt{P{n, R,C),ts) is true in all the models of CIRC[nP A ES A Gj. It 
follows that T> entails P. 

Theorem 5. [Completeness Theorem] Let T> be a consistent domain de- 
scription for process semantics and it denote the translation from the process 
semantics into the event calculus, for any process P if T> entails P, then ttT) 
entails ttP. 

Proof. Assume that V entails P; then since T> is consistent, every system de- 
velopment of the process P satisfies a set of observations for P under V. Let 
OBS{P,a,ts) represent an observation for the process P at time ts with which 
the observed value is real and we denote it as a = r. 

For any process P from T>, let x be the conjunction of ttP, ES and G without 
ES6 and Gl. 

CLRCecix] is defined as the conjunction of 

CLRC[x', Happens, Lnitiates, Terminates] State, HoldsAt] 



with 



CLRC[x', AbState; Happens, Lnitiates, Terminates , State, HoldsAt]. 

We take the first conjunct. Since all occurrences of Happens, LmplicitHappens, 
Initiates, and Terminates in y are positive. 



CIRC[x', Happens, LmplicitHappens, Initiates, Terminates] 
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is equivalent to 

CIRC[x] Happens] A CIRC[x; ImplicitHappens] A CIRC [x; Initiates] A 
CIRC[x; Terminates]. 

Since there are no occurrences of State, HoldsAt in from Theorem 3, ap- 
plying Theorem 2 to each conjunct in this formula, it can be seen that Happens, 
ImplicitHappens, Initiates, Terminates and Holds are true in all of its models 
under circumscription. 

We take the second conjunct of CIRC ec\x\- The only abnormal combinations 
of true elements are those which include both {P, False) and {P, True) for P. So, 
in all models of 

CIRC[x', AbState] Happens, Initiates, Terminates] 



we have 

Abstate(s) ^ (3P) [{P, False) G s A {P, True) G s] 

Since there are no occurrences of State, HoldsAt in y, we allow these pred- 
icates to vary, which does not affect the outcome of circumscription. So, the 
formula above is also true in all models of CIRC ec[x\- 

Since (Gl) and (ES6) are chronological, by applying Theorem 1, CIRC[xA 
GIAESC)] \= CIRC[x]. 

The combination of axioms {ES) with the general rules (G) ensures that for 
the process P from T>, in all models under circumscription we have 

(3s) {State {t, s) A HoldsIn{P{n,R,C),s)). 

It follows that HoldsAt {P{n, R, C),t) is true in all of models of CIRC[x A Gl A 
ES6]. 

For every system development of the process P under T>, we have the obser- 
vation OBS{P, a, ts) with which the observed value a = r ( r is a real) at the 
time ts- Thus, for a G (i?UG) and a = r in T>, we have CIRC ec[xI^Gl f\ESC] \= 
HoldsAt {P{n, R,C),ts) A a £ {RLI C) A a = r. It follows that ttV entails ttP. 

7 Concluding Remarks 

In this paper we have provided a method to represent the process semantics 
in the event calculus. For specifying the properties of continuous change, the 
concept of process, event and state transition law of the process semantics are 
formalized in the event calculus, based on the described general translation rules. 
We further have proved the soundness and completeness of the event calculus 
with respect to the process semantics. 

Only a handful of other authors have given attention to the problem of us- 
ing logic to represent continuous change. Based on the event calculus, some 




132 Chunping Li 



techniques were presented for representing continuous change to complement 
its existing capability for discrete change. For example, Shanahan [11, 12] out- 
lined a framework for representing continuous change based on the ontology of 
events. Belleghem, Denecker and de Schreye [2] presented an abductive version 
of event calculus for this purpose. All of these approaches can be embedded in 
logic programming but are not yet defined in a high-level description semantics 
for processes and continuous change, which is in contrast to our method. 
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Abstract. Janhunen et al. [14] have proposed a translation technique 
for normal logic programs in order to capture the alternating fix-points 
of a program with the stable models of the translation. The same tech- 
nique is also applicable in the disjunctive case so that partial stable 
models can be captured. In this paper, the aim is to capture Przymusin- 
ska and Przymusinski’s stationary extensions with Reiter’s extensions 
using the same translational idea. The resulting translation function is 
polynomial, but only weakly modular and not perfectly faithful. For- 
tunately, another technique leads to a polynomial, faithful and modular 
(PFM) translation function. As a result, stationary default logic (STDL) 
is ranked in the expressive power hierarchy (EPH) of non-monotonic log- 
ics [13]. Moreover, reasoning with stationary extensions as well as brave 
reasoning with regular extensions (i.e., maximal stationary extensions) 
can be implemented using an inference engine for reasoning with Reiter’s 
extensions. 



1 Introduction 

Quite recently, Janhunen et al. [14] have proposed a translation for normal logic 
programs. Using this translation the alternating fix-points of a program P [23] 
can be captured with the stable models [5] of the translation TrAFp(-P)- This is 
interesting, since the alternating fix-points of P include the well-founded model 
of P [25], the stable models of P [5] as well as the regular models of P [26]. 
Formally speaking, an alternating fix-point M of P satisfies (i) M = Pfi{M) 
and (ii) M C Pp{M) where Pp is the famous Gelfond-Lifschitz operator [5] and 
Tp corresponds to applying Pp twice. Such a fix-point M can be understood as 
follows: M and M' = Pp{M) specify true and possibly true atoms, respectively. 
Thus M induces a partial (or three-valued) model of P in which an atom a can be 
true (a G M), undefined (a G M' — M) or false (a ^ M'). Note that M becomes 
a (total) stable model of P if M = M' . These observations justify the view 
that the translation function Tcafp lets us to unfold partiality under the stable 
model semantics [14]. A similar setting arises in conjunction with disjunctive 
logic programs: partial stable models [20] can be captured with total ones [6]. 

Since normal and disjunctive logic programs can be seen as special cases of 
Reiter’s default theories [22] one could expect the same translational idea can 
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be applied to Reiter’s default logic (DL). In this context, Przymusinska and 
Przymusinski have proposed a partial semantics for default logic [19]: stationary 
extensions of default theories are analogous to alternating fix-points of normal 
logic programs (an equivalent notion is used by Dix [4]). One of the main goals of 
this paper is to analyze the possibilities of generalizing the translation XrAFp(-P) 
for default theories under stationary extensions. Moreover, the author [13] has 
used polynomial, faithful, and modular (PPM) translation functions in order to 
classify non-monotonic logics by their expressive powers. As a result of this 
analysis, the expressive power hierarchy of non-monotonic logics (EPH) was 
obtained. Further refinements to EPH are given in [12]. From the perspective of 
EPH, it would be important to find out the exact position of stationary default 
logic (STDL) in EPH. A crucial step in this respect is that we succeed to embed 
STDL to conventional DL using a PFM translation function. 

The rest of the paper is organized as follows. Basic notions of DL and STDL 
are reviewed in Sections 2 and 3, respectively. Then the classification method 
based on polynomial, faithful and modular (PFM) translation functions is intro- 
duced in Section 4. These properties of translation functions play an important 
role in the subsequent analysis. Starting from the translation function proposed 
for normal and disjunctive logic programs by Janhunen et al. [14], a prelimi- 
nary translation function Trsxi for default theories is worked out in Section 5. 
Unfortunately, this translation function turns out to be unsatisfactory: it is not 
perfectly faithful and it is only weakly modular. These problems are addressed in 
Section 6 where another translational technique is applied successfully: a PFM 
translation function XrsT 2 is obtained. In addition, comparisons with other log- 
ics in EPH are made in order to classify STDL properly in EPH. Brave reasoning 
with regular extensions turns also to be manageable via XrsT 2 - Finally, the con- 
clusions of the paper are presented in Section 7. Future work is also sketched. 

2 Default Logic 

In this section, we review the basic definitions of Reiter’s default logic [22] in the 
propositional case. The reader is assumed to be familiar with classical proposi- 
tional logic (CL). We write L{A) to declare a propositional language L based on 
propositional connectives (->, A, V, ^) and constants (truth T and falsity 
_L) and a set of propositional atoms A. On the semantical side, propositional 
interpretations I C A and models MCA are defined in the standard way. The 
same applies to conditions when a sentence 4> G Cis valid (denoted by ^ (f) and 
a propositional consequence of a theory T C C (denoted by T \= 4>). The theory 
Cn(T) = {^ G £ I T ^ is the closure of a theory T C £ under propositional 
consequence. A sentence (j> G £ is consistent with a theory T C £ (denoted by 
T*(j>) whenever TU{^} is propositionally consistent, i.e. TU{4>} has at least one 
model. Note that T * <j> T ^ ~^(j) holds in general. Moreover, T * T expresses 
that a theory T C £ is propositionally consistent, i.e. T _L. 

In Reiter’s default logic [22], basic syntactic elements are default rules (or 
simply defaults) which are expressions of the form q,^ j3\, ... ,!3n. 
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and 7 are sentences of L. The intuition behind such a rule is that if the 'pre- 
requisite a has been inferred and each of the justifications j3i is (separately) 
consistent with our beliefs, then the consequent 7 can be inferred. A default the- 
ory in a propositional language C{A) is a pair {D, T) where Z? is a set of defaults 
in L and T C £ is a propositional theory. For a set of defaults D, we let Cseq(ZZ) 
denote the set of consequents {7 | g appear in D. 

The semantics of a default theory {D,T) is determined by its extensions, 
i.e. sets of conclusions that are propositionally closed theories associated with 
{D, T). Rather than presenting Reiter’s definition of extensions [22] we resort to 
one by Marek and Truszczyhski [16]. The justifications of a set of defaults are 
interpreted as follows. For any E G C, the reduct De contains an (ordinary) 
inference rule - whenever there is a default “Ai.-.-An g g^^h that E * Bi 
for all i G {1, . . . , n}. Given T C C and a set of inference rules i? in £, we let 
Cn'^(r) denote the closure of T under R and propositional consequence. More 
precisely, the closure Cn'^(T) is the least theory T' C C satisfying (i) T C T', 
(ii) for every rule ^ G R, a G T' implies 7 G T' , and (iii) Cn(T') C T'. The 

closure Cn'^(T) can be characterized using a proof system [11,16]. A sentence f 
is i?-provable from T if there is a sequence ^ , . . . , ^ of rules from R such that 
T U { 71 , . . . , 7 j-i} \= ai for all i G {1, . . . ,n} and T U { 71 , . . . , 7 „} \= 4>. Then 
(f> G C is i?-provable from T 4> G Cn'^(T). The definition of extensions follows. 

Definition 1 (Marek and Truszczynski [16]). A theory E C C is an exten- 
sion of a default theory {D,T) in C if and only if E = Cn'°®(T). 

By default logic (DL) we mean default theories under Reiter’s extensions. It is 
not necessary that a default theory {D, T) has a unique extension nor extensions 
at all. Typically two approaches are used. In the hrave approach, it is sufficient to 
find one extension E containing the query (f G C. In the cautious approach, the 
query <j) G C should belong to every extension, i.e. the intersection of extensions. 



3 Stationary Default Logic 

As already stated, the existence of Reiter’s extensions is not guaranteed in gen- 
eral. Motivated by the well-founded semantics [24] and alternating fix-points [23] 
of normal logic programs, Przymusinska and Przymusinski [19] propose a weaker 
notion of extensions as a solution to the problem. Dix [4] considers an equivalent 
semantics in order to establish a cumulative variant of DL. 

Definition 2 (Przymusinska and Przymusinski [19]). A theory E C £ is a 

stationary extension of a default theory {D, T) in £ if and only if E = Cn'^®' (T) 
holds for the theory E' = Cn'°®(T) and E C E' . 

The intuition is that the theory E provides the set of actual conclusions asso- 
ciated with {D, T) while E' can be understood as the set of potential conclusions 
(cf. the alternating fix-points of normal logic programs described in the intro- 
duction). This explains why the requirement E C E' is reasonable, i.e. actual 
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conclusions must also be potential conclusions. Note that if (in addition) E' C E 
holds, then E = E' is a, Reiter-style extension of {D,T). By stationary default 
logic (STDL) we mean default theories under stationary extensions. 

Every default theory {D, T) is guaranteed to have at least one stationary 
extension E known as the least stationary extension of (D,T). It serves as an 
approximation of any other stationary extension E of (D,T) in the sense that 
E C E. This applies equally to any Reiter-style extension E of {D, T) which is 
also a stationary extension of {D,T). Complexity results on DL [7] and STDL 
[8] support the approximative view: cautious reasoning with Reiter’s extensions 
(a n^-complete decision problem) is strictly more complex than cautious reason- 
ing with stationary extensions (a A^-complete decision problem). The least sta- 
tionary extension of a finite default theory {D, T) can be iteratively constructed 

[4,19]. Initially, let Eq = tb and Eg = Cn^®(T). Then compute Ei = Cn (T) 
and E[ = Cn'^®* (T) for z = 1,2,... until Ej = Ei_i holds. For instance, the set of 
defaults D = and the theory E = {b — > p, c ^ p} 

(adopted from [11, Example 10.18]) give rise to the following iteration sequence: 
Eg = 0, El = Cn({b V c, p, s}), E 2 = Cn({b V c, p, s, r}) and Eg = E 2 . Conse- 
quently, the theory E 2 is the least stationary extension of {D,T). In fact, E 2 is 
the unique (Reiter-style) extension of (D,T), as E 2 = E^. 

There are two ways to distinguish propositionally consistent stationary ex- 
tensions of a default theory {D,T). The first one is simply to require that E is 
propositionally consistent. The other demands that the set of potential conclu- 
sions E' = Cn'°® (T) is propositionally consistent, too. In the latter case, we say 
that E is strongly propositionally consistent. Let us highlight the difference of 
these notions of consistency by a set of defaults D = {^, b}). 

Now (E,0) has three stationary extensions: E\ = Cn({b}), E 2 = Cn({a,b}), 
and Eg = Cn({^a, b}). The respective sets of potential conclusions are E( = C, 
E '2 = E 2 , and Eg = Eg. Thus Ei is (only) propositionally consistent while E 2 
and Eg are strongly propositionally consistent. 



4 PFM Translations Functions and EPH 

In this section, we recall the classification method [12,13] which has been de- 
signed for comparing the expressive powers of non-monotonic logics. In the se- 
quel, we assume that non-monotonic logics under consideration use a proposi- 
tional language £ as a sublanguage. Therefore, we let {X, T) stand for a non- 
monotonic theory in general. Here T C £ is a propositional theory and X is a set 
of parameters specific to the non-monotonic logic L in question. For instance, 
the set of parameters X is a set of defaults in default logic. We let ||(X, £)[[ 
stand for the the length of {X, T) in symbols. 

Generally speaking, a translation function Tr : Li ^ £2 transforms a theory 
{X, T) of one non-monotonic logic L\ into a theory of another non-monotonic 
logic £ 2 - Both logics are assumed to have a notion of extensions available. Our 
requirements for Tr are the following. A translation function Tr is (i) poly- 
nomial, if for all X and T, the time required to compute Tr((A, T)) is poly- 
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nomial in ||(X, T)||, (ii) faithful, if for all X and T, the propositionally con- 
sistent extensions of {X,T) and Tr((X, T)) are in one-to-one correspondence 
and coincide up to £, and (iii) modular, if for all X and T, the translation 
Tr((X, T)) = {X' ,T' U T) where {X' ,T') = Tr((X, 0 )). A translation function 
Tr : Li ^ L2 is called PFM if it satisfies all the three criteria. 

Note that a modular translation function translates the set of parameters X 
independently of T which remains untouched in the translation. For the purposes 
of this paper, we distinguish also weakly modular translation functions considered 
by Gottlob [ 9 ]. A translation function Tr is weakly modular, if for all X and 
T, Tr((A,T)) = {X',T' U t{T)) where {X',T') = Tr((A, 0 )) and t is a separate 
translation function for T. Note that the translation of X remains independent 
of the translation of T even in this setting. 

Given two non-monotonic logics Li and L2, we write Li ppm L2, if there 
exists a PFM translation function Tr : Li ^ ^2- Then L2 is considered to be 
as expressive as Li. In certain cases, we are able to construct a counter-example 
which shows that a translation function satisfying our criteria does not exist. We 
use the notation Li T2 in such cases and we may also drop any of the three 
letters (referring to the three criteria) given that the corresponding criterion is 
not needed in the counter-example (note that Li Fm L2 implies Li iT™ L2, for 
instance). Further relations are definable for non-monotonic logics in terms of 
the base relations p™ and fi™ : (i) Li is less expressive than L2 (denoted by 
L\ p™ L2) if L\ PPM L2 and L2 p™ Ti, (ii) L\ and L2 are equally expressive 
(denoted by Li ppm L2) if Ti ppm L2 and L2 ppm Li, and (iii) Li and L2 are 



mutually incomparable (denoted by Li p(.m L2) if Li ji™ L2 and L2 Li- 



In Fig. 1 , we have depicted the current EPH us- 
ing only single representatives of the classes that have 
been obtained from DL via syntactic restrictions. Nor- 
mal DL (NDL) is based on defaults of the form 

In prerequisite-free DL (PDL) only defaults of the form 
T./ 3 i^..,/ 3 n allowed. The third variant (PNDL) is a 

hybrid of NDL and PDL with defaults of the form 
The semantics of these syntactic variants is determined 
by Reiter’s extensions. Recall that GL stands for propo- 
sitional logic. The reader is referred to [ 12 , 13 ] for the 
complete EPH with 11 non-monotonic logics. 



DL 




PDL 



PNDL 



GL 



Fig. 1: Classes of EPH 
Represented by Syntac- 
tic Variants of DL 



5 A Weakly Modular Translation 

The goal of this section is to generalize the translation proposed by Janhunen 
et al. [ 14 ] so that the stationary extensions of a default theory {D, T) can be 
captured with the (Reiter-style) extensions of the translation. For a while, we 
restrict ourselves to the case of normal logic programs in order to explain the 
ideas behind the translation function Tcapf discussed in the introduction. The 
way to represent partial models of a normal logic program P is to introduce a 
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new atom a* for each atom a that appears in P. The intuitive reading of a* 
is that a is potentially true. Then undefined atoms are captured with a total 
model N as follows: an atom a is undefined in a partial model if and only if a is 
false in N and a* is true in N . The translation TrAFp(^*) is obtained as follows: 
a rule of the form a <— bi, . . . , b„, ~Ci, . . . , is translated into two rules 
a 4— bi, . . . , b„, ~c*, . . . , and a* b*, . . . , b* , ~Ci, . . . , ~Cm. In addition, a 
rule of the form a* ^ a is introduced for each atom a that appears in P. Rules 
of the latter type make sure that any atom that is true is also potentially true 
(cf. Section 1). As a result of this transformation on the rules of P, the stable 
models of TrAFp(^’) capture the alternating fix-points of P exactly. 

Let us now devise an analogous translation for a default theory {D, T) in a 
propositional language C{A). A new atom a* is introduced for each atom a G A 
and we define A* — {a* | a G A} for any set of atoms A C A. Since propositional 
logic is based on a much richer syntax than bare atoms, we have to find a way to 
express that an arbitrary sentence ^ G is a potential conclusion (i.e. a member 
of E' in Definition 2). As a solution, we introduce a sentence (p* for each p € C. 

Definition 3. The sentences 4> of C{A) are translated by the following rules: (i) 
(T)* = T, (a) (T)* = ±, (Hi) (a)* = a* for an atom a G A, (iv) (“'V’)* = “'(V’)*; 
and (v) (ipi o = (V’l)* ° (V’ 2 )* for any connective o G {A, V, 

By this definition, any sentence <j) G C{A) is translated into a sentence p* 
in the propositional language £* based on A* . For instance, (^a ^ (b V T))* is 
rewritten as ^a* (b* V T). For a theory T C C and a set of inference rules 

i? in £, we let T* and R* stand for the theory {^* | ^ G T} C £* and the set 
of inference rules | ^ G i?} in £*, respectively. The following lemmas state 
some useful properties of theories involving sentences from C and C* . 

Lemma 1. Let T C C{A) and S C C{A) he theories so that S* C C*{A*) and 
T U S'* C C{A U A*). Consider any p G C{A). Then (i) (T \J S') *T ^ T 
and S' * T, (ii) if S' * T, then (T U S') * p T * p and T U S' ^ p T \= p, 
and (Hi) ifT * T, then {T U S') * p' S' * p' and TU S' \= p' T' \= p' . 



Lemma 2. Let T he a propositional theory in L{A) and p € C any sentence. 
Then it holds that (i) T * p T' * p' , (ii) T ^ ^ T* |= p' , (Hi) [Cn(T)]* = 
Cn(T*), and (iv) [Cn^(T)]* = Cn^’(T*). 

The generalization of TrAPF for default theories follows. 



Definition 4. For any default theory (D,T) in C{A), let TrsTi((D,T)) = 



({ 






1 * 



1 



u{^| 7€ Cse(7(D)},rur*). 



The intuition behind the translation is to capture a stationary extension E 
of (D, T) as well as the associated set of potential conclusions E' with an exten- 
sion Cn(A U {E'Y) of the translation TrsTi((D, T)). The defaults of the forms 
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and ° capture the closures Cn^®' (T) and (Cn^®(T)) , re- 

spectively. The latter closure (i.e. {E')*) is encoded in £* rather than C. The 
defaults of the form ^ enforce the relationship E C E' , i.e. actual conclusions 
have to be potential as well. Using Lemmas 1 and 2, we may compute the reduct 
of the set of defaults D' involved in the translation TrsTi((T*, T)). 

Proposition 1. Let (D,T) be a default theory in C{A) and {D',T\JT*) the 
translation Ttsti{{D,T)) in C {AiJ A*). Moreover, let E = Cxi{Ei \J E 2 *) hold 
for propositionally consistent theories E\ and E 2 in L. Then for g jj^ 

(i) ^ G D'e ^ G Dei, (a) ^ G D'e ^ G De 2, and (Hi) G D'e- 

Using these relationships of D'e, De^ and De2 as well as Lemmas 1 and 2, 
it can be shown that Trsxi captures stationary extensions in the following way. 

Theorem 1. Let (D,T) be a default theory in C{A) and {D',T U T*) the trans- 
lation TrsTi((T^, T)) in L' {A^ A*). If Ei C C is a strongly propositionally con- 
sistent stationary extension of {D,T) and E 2 = Cn'°®i(T), then E = Cn{Ei U 
E 2 *) C C' is a propositionally consistent extension of {D', T U T*). 



Theorem 2. Let {D,T) be a default theory in C{A) and {D' ,T U T*) the trans- 
lation TrsTi((T^, T)) in L'{A^ A*). If E C C is a propositionally consistent 
extension of {D' ,T U T*) , then E\ = E C\ L is a strongly propositionally con- 
sistent stationary extension of (D,T) such that E 2 = {4> G C \ (j>* G E} satisfies 
E2 = Cn^®i (T). 



A shortcoming of the translation function Trsxi is that it is unable to cap- 
ture stationary extensions of a default theory (D,T) that are propositionally 
consistent but not strongly propositionally consistent. In other words, Trsxi 
is not faithful in the sense it is required in Section 4. Let us recall the set of 
defaults D = &om Section 3 in order to demonstrate this fea- 



ture of TrsTi- The translation TrsTi((T*, 

T~\f f T :a T :a* T :^a T :^a* T : T : b: a: 

^ t a* ’ a ’ ^a* ’ ^a ’ b ’ b* ’ b* ’ a* 



= {D' ,%) where the set of defaults 
v}. The default theory (D',0) has 
two extensions E '2 = Cn({a, a*, b, b*}) and E'^ = Cn({^a, ^a*, b, b*}) corre- 
sponding to the stationary extensions E 2 = Cn({a,b}) and U 3 = Cn({^a,b}) 
of {D,tti). However, there is no extension corresponding to the stationary exten- 
sion El = Cn({b}) of (D,0), since E\ is not strongly propositionally consistent. 
Nevertheless, the translation function Trsxi is very close to being faithful. 



Theorem 3. Let {D, T) be a default theory in C{A) and {D' , T U T*) the trans- 
lation TrsTi{{D,T)) in £'(AU A*). Then the strongly propositionally consistent 
stationary extensions of (D,T) and the propositionally consistent extensions of 
(£)',TUT*) are in one-to-one correspondence and coincide up to L. 



There is a further reason to consider Trsxi as an unsatisfactory transla- 
tion function: it is only weakly modular. This is because Trsxi duplicates the 
propositional subtheory T in £*, i.e. it forms the theory TUT*. To enforce 
full modularity, we should generate T* in terms of defaults. It is shown in the 
following that this is not possible if we wish to keep Trsxi polynomial. 
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Proposition 2. It is impossible to translate a finite set of atoms A into a fixed 
set of defaults D in £'(^U A*) such that (i) the time needed to translate A is 
polynomial in |^| and (ii) for all T C L{A), the theory (D,T) has a unique 
extension E = Cn(T U T*) C 

Proof. It is worth stating some relevant properties of propositional logic. Con- 
sider a fixed propositional language C{A) based on a finite set of atoms A. Any 
two propositional theories T\ C L and T 2 C £ are considered to be £-equivalent 
if Cn(Ti) = Cn(T 2 )- Consequently, there are different propositional theo- 
ries T in C up to C-equivalence. This is because the models of any propositional 
theory T Q C form a subset of the set of all interpretations {/ | / C -4} which has 
the cardinality 2^\, Of course, the number of different theories T C becomes 
infinite if £-equivalence of theories is not taken into account. Let us also recall 
that it is possible to represent any theory T C £ in a disjunctive normal form 
4>i y . . . V 4>n based on the models Mi C of T such that each disjunct is a 
conjunction of the literals in {a | a € Mi] U {^a \ a G A — Mi}. 

Let us then assume that A can be translated into a fixed set of defaults D 
in C'{AUA*) such that (i) and (ii) hold. Consequently, the length ||£)|| is also 
majored by a polynomial p(|A|). Moreover, the unique extension of {D,T) is 
of the form Cn(T U £) C £' where P C Cseq(Z?) [16] regardless of the choice 
for T. It is clear that £(|A|) provides also an upper limit for |Cseq(£))|. Since 
T C £, the theory E = Cn{T U E) has at most 2 P^A\) different projections with 
respect to £* up to £*-equivalence. Let us then consider a sufficiently large set 
of atoms A such that £(|A|) < 2^\ (this is possible regardless of the polynomial 
p(|A|)) and the set of defaults D obtained as a translation. Now the number 
of different propositional theories in £* (up to £*-equivalence) exceeds that of 
projections Cn(T U £) C £* (up to £*-equivalence) . Consequently, there is a 
theory S'* C £* which is not propositionally equivalent to any of the projections 
Cn(T U £) n £* where T C £ and E C Cseq(D). This means that {D, S) cannot 
have an extension E such that £n£* = S*. But this would be the case if {D, S) 
had a unique extension E = Cn(S U S*), a contradiction with (ii). □ 

However, there is a modular but exponential translation of A into a set of 
defaults that satisfies the second criteria of Proposition 2. Given a finite set of 
literals L = {^i, . . . , l„}, we write \J L to denote the sentence Zi V . . . V A set of 
atoms A is translated into a set of defaults D = { \ L C AU {-aja G A}}. 
The length of D grows exponentially in |A|. Since each finite T C C{A) is 
equivalent to a sentence (V £ 1 ) A ... A (V L„) in a conjunctive normal form 
where each Li C AUj^ajaG A}, it is clear that the unique extension E of 
{D,T) contains exactly the logical consequences of (V £ 1 ) A ... A (V £„) and 
(V £ 1 *) A ... A (V £«*)• Thus E = Cn(T U T*) results for all T C L{A). 



6 A Fully Modular Translation 

The analysis in Section 5 reveals two weaknesses of the translation function 
TrsTi) as it is only weakly modular and it is not faithful, i.e. it does not cap- 
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ture all propositionally consistent stationary extensions. In this section, we shall 
consider another technique in order to overcome these shortcomings of Trsxi- 
The technique is adopted from [1] where Bonatti and Eiter embed DL into PDL 
(such a translation cannot be PFM, as indicated by the classes of EPH [13]). 
In their approach, new atoms are introduced as guards (i.e., as antecedents of 
implications) in order to encode several propositional theories in one. 

Before demonstrating guarding atoms in practice, let us introduce some 

notation. Given T C C{A) and a new atom g ^ we let T® denote the 

theory where the sentences of T are guarded by g. Similarly 

for a set of inference rules R in C{A) and a new atom g ^ we define 

I 7 € Then consider propositional theories T\ = {a, a ^ b} and 

T2 = {^b}. Using guards gi and g2, we define a theory T = U = 

{gi ^ a,gi ^ (a ^ b),g2 — > ^b}. The guards gi and g2 let us distinguish the 

two subtheories within T. For instance, T ^ gi ^ b holds, since Ti |= b holds. 
Moreover, we have that T \= ^ ^b, because T2 |= ^b holds. It is also possi- 

ble to combine guards: T ^ gi A g2 — > T holds, since T\ U T2 is propositionally 
inconsistent. Note that T remains propositionally consistent although this is the 
case. Let us then state some useful properties of theories and sentences involving 
one guarding atom (a generalization for multiple guards is also possible). 

Lemma 3. Let T\ and T2 he propositional theories in L{A) and g ^ A a new 
atom. Then it holds for any (f £ C that (i) {T\ U (T2)®) * (j> ^ Ti * (j>, (ii) 

(Ti U (T2)®) * (g A ^) AA (El U T2) * (j), (Hi) Ti U (E2)® \= 4 > Ti \= c) and (iv) 

Ti U (T2)® [= g ^ 4 A Ti U T2 h 

Our forthcoming translation will use only one guarding atom, namely p, 
which refers to any “potential” conclusion associated with a stationary exten- 
sion. This resembles our previous approach in which a potential conclusion (j) is 
encoded as (jf . Given a stationary extension Ei and E2 = Gn^®i (T), our idea 
is (i) to include Ei (i.e. the set of conclusions) without guards and (ii) to repre- 
sent E2 (i.e. the set of potential conclusions) using p as a guard. This approach 
provides an implicit encoding of the inclusion Ei C E2, since \= (j) —>■ {p ^ (f) 
holds for any propositional sentence (j) G C. This is the key observation that lets 
us to define a fully modular translation: there is no need to provide a separate 
translation for the propositional subtheory T (in contrast to Trsxi)- 

Definition 5. For any default theory {D,T) in C{A), let TrsT 2 ((D,T)) = 

^ r a:pA/3i,...,pAffn p^a:/3i ,. . .,/3n | g 

where p is a new atom not appearing in A. 

Using the first two items of Lemma 3, the reduct of the set of defaults intro- 
duced by TrsT2 may be computed. 

Proposition 3. Let {D,T) be a default theory in C{A) and {D',T) the trans- 
lation TrsT2((D,r)) in £'(Al U {p}). Moreover, let E = Gn(Ei U {E2Y) and 
El C E2 hold for theories E\ and E2 in L. Then it holds for any default 
e D that (i) ^ G D'is AA ^ G De, and (ii) ^ & D' e ^ ^ & De,. 
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By the theorems that follow, we shall establish that TrsT2 fulfills the re- 
quirements set up in Section 4 . In contrast to Trsxi) the translation function 
TrsT2 is modular and it captures also propositionally consistent stationary ex- 
tensions which are not strongly propositionally consistent. As a matter of fact, 
even propositionally inconsistent stationary extensions are captured by TrsT2- 

Theorem 4 . Let (D,T) be a default theory in L{A) and {D' ,T) the translation 
TrsT2((£^, r)) m£'(AU{p}). If Ei C C is a stationary extension of (D,T) and 
E2 = (T), then E = Cn{Ei U (E2)^) C £' is an extension of {D',T). 

Proof sketch. Let Ei be a stationary extension of {D,T) and E2 = Cn^®i(T). 
Then define the theory E = Cn(ifi U (£^2)'^) C Since Ei C E2, it follows 
by Proposition 3 that D' e = De^ U {DeiY- It remains to be established that 
Qii^e2U(DeP '‘ ij (^E2Y). (C) It can be shown by Lemma 3 that 
Cn(£i U (£2)'’) has sufficient closure properties: (i) T C Cn(£i U (£2)'’), (ii) if 
^ G De2 and a G Cn(£i U (£2)'^), then also 7 G Cn(£i U (£2)'’), (iii) if G 

{DeiY and (p ^ a) G Cn(£i U (£2)'^), then also p ^ 7 G Cn(£i U (£2)'^), and 
(iv) Cn(£iU(£2)'’) is propositionally closed in . (D) It can be shown that T' = 
shares the essential closure properties of £1 = C £ 

and (£2)^ = Cn(^®i ^ O’-, (i) TCP' and £P C T', (ii) T' is closed under 
the rules of De2 and the rules of {DEff , and (iii) T' is propositionally closed in 
C and £P. Thus £1 C T' and (£2)'’ C T' so that Cn(£i U (£2)'’) C T holds. □ 

Theorem 5 . Let (D,T) be a default theory in L{A) and (D',T) the translation 
TrsT2((£, r)) in £'(A U {p}). If E C C is an extension of the translation 
{D' ,T), then E\ = E C\ L is a stationary extension of (D,T) such that £2 = 

G £ I p ^ G £} satisfies £2 = Cn'°®i (T). 

Proof sketch. Let £ = Cn^ ®(T) be an extension of {D',T) and let £1 and £2 
be defined as above. Moreover, define £1 = {7 | — G D' e and a G £} and £2 = 
{7 I G D' E and p ^ a G £}. It follows by a characterization of extensions 

[ 16 ] that £ = Cn(£U£iU(£2)P). Thus £1 = Cn(£U£i), £2 = Cn(£U£iU£2) 
and £ = Cn(£i U (£2)'^) hold by Lemma 3 . It follows that £1 C E2. 

(A) It is established that £1 = £n£ equals to Cn'^®^ (T). (C) Consider any 
^ G £1 so that (j) € C, (j> G E and (f) is £'_E-provable from £ in z > 0 steps. It 
can be proved by induction on i that (f> G Cn^®2 (y) holds using Lemma 3 and 
Proposition 3 . (A) It can be shown using Proposition 3 that £1 has the closure 
properties of Cn^®2(y); (j) T C Ei, (ii) ii ^ G De2 and a G £1, then also 
7 G £1, and (iii) £1 = £ n £ is propositionally closed in £ C £'. 

(B) It remains to be shown that £2 equals to Cn^®i(£). (C) Consider any 

^ G £2. It follows that ^ G £ and p ^ (f> G E, i.e. p ^ is £'£;-provable from T 
in z > 0 steps. Then it can be proved by induction on z that (j) G Cn'°®i (T) holds 
using Lemma 3 and Proposition 3 . In particular, note that £1 C E2 implies 
De2 C De2- ( 3 ) It can be shown by Proposition 3 that £2 shares the closure 
properties of Cn^®i(T): (i) T C £2, (ii) if 7 G De^ and a G £2, then also 
7 G £2, and (iii) £2 = {^ G £ | p ^ G £} is propositionally closed in £. □ 
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Theorem 6. Let (D,T) be a default theory in L{A) and (D',T) the translation 
TrsT 2 ((£^, r)) zn£'(^U{p}). Then the stationary extensions of (D,T) and the 
extensions of {D' ,T) are in one-to-one correspondence and coincide up to L. 

Proof sketch. Theorems 4 and 5 provide us two implicit mappings. The first one 
maps a stationary extension E C £ of {D,T) to an extension mi (ill) = Cn{E U 
(£1')'^) of {D' ,T) where E' = Cn'°®(T). The second one maps an extension 
E (1 C oi {D' ,T) to a stationary extension m 2 (if) = if n £ of {D,T). Using 
Lemma 3 and the proof of Theorem 5, it can be shown that mi and m 2 are 
injective and inverses of each other. Moreover, the extensions involved in the 
one-to-one correspondence coincide up to £ by the definition of m 2 . □ 

From now on, our goal is to to locate the exact position of STDL in EPH 
[12,13]. The results established so far let us draw the first conclusion in this 
respect. The translation function TrsT 2 is PFM by Definition 5 and Theorems 4- 
6 (restricted to propositionally consistent extensions). We conclude the following. 

Corollary 1. STDL PFM DL. 

Theorems 7 and 8 establish that STDL resides between CL and DL in EPH. 
Theorem 7. STDL PPM DL. 

Proof. Consider a set of defaults D = m £ based on A= {a}. The de- 

fault theory (D,0) has two propositionally consistent extensions: E\ = Cn({a}) 
and E 2 = Cn({^a}). Suppose there is a PFM translation function Tr that maps 
(D, 0) to a default theory (D', T') in £' based on D M such that the propo- 
sitionally consistent extensions of the former and the propositionally consistent 
stationary extensions of the latter are in one-to-one correspondence and coincide 
up to £. Then the translation {D',T') has at least one propositionally consis- 
tent stationary extension E by the one-to-one correspondence of extensions. 
Consequently, the least stationary extension E of {D',T') is also propositionally 
consistent, since F is contained in E which is propositionally consistent. 

Then consider the extension of {D, 0) corresponding to F which is either 
El or E 2 . Let us analyze the case that Ei corresponds to F (the case that E 2 
corresponds to F is covered by symmetry). Since a € if 1 , it follows that a G F 
by the faithfulness of Tr. Then let E' be the stationary extension of {D',T') 
corresponding to E 2 . Since F C if' it follows that a G E' . Thus a € F 2 by the 
faithfulness of Tr, a contradiction. Hence DL ^ STDL and DL tf™ STDL. □ 



Theorem 8. CL PFM STDL. 

Proof. The unique extension associated with a classical propositional theory 
T C £{A) is Cn(T). Consider the translation function Tr(T) = (0,T). It is clear 
that the default theory Tr(T) has a unique stationary extension E = Cn®® (T) = 
Cn®(T) = Cn(T) regardless of T. Thus CL PFM STDL. 
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Then consider the set of defaults D = {^, ^} and the possibilities of 
translating the default theory (Z?, 0) under stationary extensions into a classical 
propositional theory T'. Now (-0,0) has three stationary extensions, namely 
El = Cn(0), E 2 = Cn({a}) and E 3 = Cn({b}). However, the translation has 
only one extension Cn(T'). Hence STDL CL and STDL pT™ CL. □ 

The set of defaults D involved in the proof of Theorem 7 is normal and 
prerequisite- free. We may conclude the following by the same counter-example. 

Corollary 2. NDL ^ STDL, PDL ^ STDL and PNDL ^ STDL. 

It remains to explore whether STDL is captured by PDL, PNDL and NDL. 
Theorem 9. STDL pi™ PDL and STDL pi™ PNDL. 

Proof. Consider the set of defaults D = {^, (adopted from [9, Theorem 

3.2]) and the theories Tp = {a}, T 2 = {a ^ b} and T 3 = {a,a ^ b} in C{A) 
where A = {a,b}. Each default theory {D,Ti) where i € {1,2,3} has a unique 
propositionally consistent stationary extension E = Cn({a,b|). Then suppose 
that there is a PPM translation function TrpDL from STDL to PDL. Let {D', T') 
be the translation TrpDL((-D, 0)) in £'{A') where A' D A. Since TrpDL is modu- 
lar, we know that TrpDL((-D, 7i)) = {D', T' U Ti) holds for every i G (1,2, 3}. By 
the faithfulness of TrpDL, each default theory {D' , T' U Ti) with z G {1, 2, 3} has 
a unique propositionally consistent extension E) such that E = E^C] C. Since D' 
is prerequisite-free, each extension E[ is of the form Cn(T' U Tz U Ei) where Ei 
is the set of consequents {7 | ^ £)/ Vj G (1, . . . , n} : .E' * Pj}. 

Since a ^ b G E H £, it follows that a ^ b G E{ holds for E[ = Cn(T' U Ei U 
El). Thus E[ = Cn(E' U E 3 U El) so that E[ is also a propositionally consistent 
extension of {D',T' U E 3 ). On the other hand, it holds that a G E n £. Thus 
a G E^ holds for E^ = Cn(E' U E 2 U E 2 ). It follows that E^ = Cn(E' U E 3 U £ 2 ), 
i.e. E 2 is also a propositionally consistent extension of {D',T' U E 3 ). 

Then E[ = E '2 = Eg is the case, as Eg is the unique propositionally consistent 
extension of {D' ,T' U Eg). It follows that Ei = E 2 = Eg as well. Thus we let E' 
denote any of E(, Ei^ and Eg, as well as E any of Ei, E 2 and Eg. Recall that 
E' is a propositionally consistent extension of (E',E'UEi) and b G E', since 
b G E. It follows that T' U (a) U E ^ b as well as that E' U E |= a ^ b. Thus 
E' = Cn(E'UE 2 UE) = Cn(E'UE) holds, indicating that E' is also an extension of 
(E', E'). A contradiction, since a G E' and b G E', but the unique propositionally 
consistent stationary extension of (E,0) is Cn(0). Hence STDL pi™ PDL. 

Let us then assume that STDL ppm PNDL. Since PNDL pfm PDL holds by 
the classes of EPH, we obtain STDL ppm PDL by the compositionality of PFM 
translation functions [13], a contradiction. Hence STDL pi™ PNDL. □ 
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Theorem 10. STDL NDL. 

Proof. Consider a set of defaults Z? = { } and a theory T = {a} in £({a}). Note 
that the default theory {D,T) has no propositionally consistent stationary ex- 
tensions. Suppose there is a PFM translation function Tr such that Tr((D, T)) = 
{D',T' U T) is a normal default theory which guaranteed to have an extension 
E' [22]. Since Tr is faithful, E' must be propositionally inconsistent. Thus T'UT 
must be propositionally inconsistent [22]. It follows that T' [= ^a. 

On the other hand, the default theory (ZZ, 0) has a propositionally consis- 
tent stationary extension E = Cn(0). By modularity, the translation Tr((Zl,0)) 
is {D',T'). By faithfulness, the translation {D',T') has a corresponding propo- 
sitionally consistent extension E = Cn^^(T') such that E = F n C. Since 
T' [= ^a, it follows that £ F. A contradiction, since ^a ^ E = Cn(0). □ 

By the theorems presented, STDL is incomparable with PDL, PNDL and 
NDL. Thus STDL is located in its own class of EPH (not present in Fig. 1). 

6.1 Regular Extensions 

Let us address a further semantics for default logic which is obtained as a gen- 
eralization of regular models proposed for normal logic programs by You and 
Yuan [26] . An alternating fix-point M of a normal logic program P is a regular 
model of P if there is no alternating fix-point M' of P such that M C M' . In 
this way, regular models minimize undefinedness. Stable models of P are also 
regular models of P but in general, a normal logic program may possess more 
regular models than stable models. Regular extensions are definable for default 
theories in an analogous fashion as maximal stationary extensions. 

Definition 6. A stationary extension E of a default theory {D,T) is a regular 
extension of (D,T) iff {D,T) has no stationary extension E' such that E C E' . 

Despite this maximization principle, stationary and regular extensions be- 
have very similarly under the brave reasoning approach. More precisely, a query 
(j) belongs to some regular extension Zf of a default theory {D, T) if and only if 
(j) belongs to some stationary extension of (D,T). By this tight interconnection 
of decision problems, Gottlob’s complexity results [7,8] imply that brave reason- 
ing with regular extensions forms a S^-complete decision problem in analogy 
to brave reasoning with stationary extensions. The results of this paper enable 
implementing brave reasoning with stationary and regular extensions. In addi- 
tion to an inference engine for brave reasoning with Reiter’s extensions (such 
as the system DeReS [2]) we need a program that computes the translation 
Ttst 2 {{D,T)) for a default theory {D,T) given as input. 

7 Conclusions and Future Work 

In this paper, we have analyzed the possibilities of reducing stationary default 
logic (i.e., default theories under stationary extensions) to Reiter’s default logic 
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(i.e., default theories under Reiter’s extensions). It turned out that the transla- 
tion function proposed for normal and disjunctive logic programs [14] does not 
generalize for default theories in a satisfactory way. In fact, it is established in 
Section 5 that a PFM translation function cannot be obtained using a similar 
technique. Fortunately, guarding atoms provide an alternative technique that 
leads to a PFM translation function in Section 6. This is how we obtain further 
evidence for the adequacy of PFM translations, because even non-monotonic 
logics with a partial semantics can be classified using the existence of a PFM 
translation function as the criterion. It is also interesting to note that TrsT 2 
does not specialize for normal nor disjunctive logic programs, since conditional 
inference with guards is not supported by them. However, the situation could 
be different if nested logic programs [15] are taken into consideration. Moreover, 
the properties of stationary and regular extensions and the translation function 
TrsT 2 enable implementing brave reasoning with stationary and regular exten- 
sions simply by using existing implementations of DL (such as DeReS [2]). 

By the theorems presented, the stationary default logic (STDL) is strictly 
less expressive than default logic (DL), but strictly more expressive than clas- 
sical propositional logic (CL). Moreover, STDL is incomparable with the other 
representatives of the classes of EPH: NDL (normal DL), PDL (prerequisite- free 
DL) and PNDL (prerequisite-free and normal DL). Thus STDL determines a 
class of its own between CL and DL. This is quite understandable, since STDL 
is the only non-monotonic logic based on a partial semantics and located in 
EPH. Nevertheless, the results of this paper indicate that EPH can be extended 
further with semantic variants of default logic. Only weak default logic (WDL) 
has been considered earlier while a number of syntactic variants have been al- 
ready classified. One obvious way to extend EPH is to analyze syntactic variants 
of default logic under stationary extensions. Moreover, analogs of stationary 
extensions [10,3] have been proposed for Moore’s autoepistemic logic [18] and 
Reiter’s closed world assumption (CWA) [21] can be understood as the “station- 
ary counterpart” of McCarthy’s circumscription [17] as shown in [11]. It seems 
that a partial fragment of EPH can be established by comparing STDL with 
these logics such that STDL links this fragment to the rest of EPH. 
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Abstract. We present an abductive mechanism that works as a robust 
parser in realistic tasks of Natural Language Processing involving in- 
complete information in the lexicon, whether it lacks lexical items or the 
items are partially and/or wrongly tagged. The abductive mechanism 
is based on an algorithm for automated deduction in Lambek Calcu- 
lus for Categorial Grammar. Most relevant features, from the Artificial 
Intelligence point of view, lie in the ability for handling incomplete infor- 
mation input, and for increasing and reorganizing automatically lexical 
data from large scale corpora. 



1 Introduction 

1.1 Logic and Natural Language Processing 

Natural Language Processing (NLP) is an interdisciplinary field where lots of re- 
search communities meet. Out of all NLP objectives, parsing is among the basic 
tasks on which other treatments of natural language can be founded. Develop- 
ment of efficient and robust parsing methods is a pressing need for computational 
linguistics; some of these methods are also relevant to Logic in AI whether they 
are founded on Logic or they use AI characteristic techniques. 

Lambek Calculus (LC) for Categorial Grammar (CG) is a good candidate 
for developing parsing techniques in a logic framework. Some of the major ad- 
vantages of CG lie in: (a) its ability for treating incomplete subphrases; (b) it is 
(weakly) equivalent to context free grammars, but (c) CG is radically lexicalist, 
it owns no (production) rule except logical ones; therefore, (d) syntactic revisions 
are reduced to type reassignments of lexical data of a given lexicon. 

On the other hand, the Gentzen-style sequent formulation of LC for CG also 
presents several attractive features: (a) a well-known logical behaviour — LC 
corresponds to intuitionistic non-commutative multiplicative linear logic with 
non empty antecedent; (b) the cut-rule elimination, and hence the subformula 
property that is desirable with regard to its implementation. 
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Ciencia y Tecnologia. We would like to thank two anonymous referees for their 
valuable comments. 
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When it comes to using LC in realistic tasks of NLP, one must admit that 
LC has two possible disadvantages: (a) its complexity is unknown; (b) in so 
far as it is equivalent to context free grammars, LC cannot account for several 
linguistic phaenomena. These limitations accepted, we encounter another kind of 
dificulties: the realistic tasks of NLP involve characteristic problems that cannot 
be solved by the sole use of deductive systems. A deduction is always something 
closed, in accordance with immovable rules; however our language understanding 
is robust enough and it succeeds even if partial information is lacking. 



1.2 Learning and Revising Data 

The AI researches intend to enlarge the logical machinery from the precise math- 
ematical reasoning to the real situations in the real world. That means, for ex- 
ample: to learn from experience, to reorganize the knowledge, to operate even if 
the information is incomplete. The task of building robust parsers comes right 
into the goals of AI in a natural way. 

The (informal) notion of robustness refers to the indifference of a system to 
a wide range of external disruptive factors [Ste92] , [Men95] . Out of all desirable 
properties of a robust parser we focus on two ones chiefly: (a) a robust parser 
has to work in absence of information (hence it must learn from data); (b) a 
robust parser has to revise and to update the information. 

In the last years, the idea that systematic and reliable acquisition on a large 
scale of linguistic information is the real challenge to NLP has been actually 
stressed. Moreover, currently available corpora make it is possible to build the 
core of a grammar and to increase the grammatical knowledge automatically 
from corpora. Two strategies vie with each other when it comes to approach- 
ing the specific problems of NLP we refer before: statistical versus rule-based 
strategies. From an engineering point of view, statistical extensions of linguistic 
theories have gained a vast popularity in the field of NLP: purely rule-based 
methods suffer from a lack of robustness in solving uncertainty due to overgen- 
eration (if too many analyses are generated for a sentence) and undergeneration 
(if no analysis is generated for a sentence) [Bod98]. We think this ‘lack of robust- 
ness’ can be filled in the AI intention using abductive mechanisms that enlarge 
the deductive systems. 



1.3 Abductive Mechanisms 

We use the terms ‘abductive mechanism’ in a sense that may require a deeper 
explanation. 

A deductive logical system typically offers a ‘yes/no’ answer to a closed ques- 
tion stated in the language of this logic. The two situations pointed out above 
can be found whenever we try to use a deduction system in realistic tasks of 
NLP: 

(a) Lack of information in the lexicon. Thus, we have to use variables that do 
not belong to the logical language — ct{X ) — for unknown values . An equivalent 
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problem in classical logic would be the following task: p\/ q,p ^ r, X \- r. Stated 
in this way, it is not a deduction problem properly. 

(b) A negative answer merely: a. 

In both cases we could consider we have a theory (here, the lexicon, L) and a 
problem to solve: how the lexicon has to be modified and/or increased in order 
to obtain a deduction: 

(a’) L h Subsxa{X), where A belongs to the used logical language; 

(b’) L\- (3, where (3 is obtained from a according to some constraints. 

That is precisely what we have called ‘abductive’ problems (inasmuch as it 
is not a new rule, but new data that have to be searched for), and ‘abductive 
mechanism’ (as the method for its solution). One matter is the logical system 
on whose rules we justify a concrete yes/no answer to a closed question, and 
another matter is the procedure of searching for some answer, that admits to be 
labelled as abductive. 

Our purpose is to introduce an abductive mechanism that enlarges LC in 
order to obtain a robust parser that can be fruitfully employed in realistic ap- 
plications of NLP. ^ 



1.4 State-of-the-Art in Categorial Grammar Learning 

Large electronic corpora make the induction of linguistic knowledge a challenge. 
Most of the work in this field falls within the paradigm of classical automata and 
formal language theory [HU79], whether it uses symbolic methods, or statistical 
methods, or both.^ As formal automata and language theory does not use the 
mechanisms of deductive logics, the used methods for learning a language from 
a set of data are not abductive or inductive mechanisms. Instead, they build an 
infinite sequence of grammars that converges in the limit. 

This being the background, much of the work about learning Categorial 
Grammars deals with the problem of what classes of categorial grammars may 
be built from positive or negative examples in the limit. ^ This approach manages 
corpora that hold no tags at all, or that are tagged with the information of which 
item acts as functor and which item acts as argument. 

The difference between those works and ours is that the former ones (a) have 
a wider goal — that of learning a whole class of categorial grammars from tagged 
corpora — , and (b) that they do not make use of any abductive mechanism, but 
follow the steps made in the field of formal language theory. 

^ Currently, LC seems to be relegated to an honourable logical place. It is far from 
constituting an indispensable methodology in NLP. Let us use the TMR Project 
Learning Computational Grammars as an illustration. This project “will apply sev- 
eral of the currently interesting techniques for machine learning of natural language 
to a common problem, that of learning noun-phrase syntax.” Eight techniques are 
used. None is related to LC. 

^ Cfr. Gold [Gol67], Angluin [AngSO], [AS83], Bod [Bod98] and references therein. 

® For this approach, cfr. Buszkowski [Bus87a], [Bus87b], Buszkowski and Penn [BP90], 
Marciniec [Mar94], Kanazawa [Kan98]. 
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On the other hand, our work is (i) of a narrower scope — we are only interested 
in filling some gaps that the lexicon may have, or we want to change the category 
assigned by the lexicon to some lexical item when it does not lead to success — , 
and (ii) we use an abductive mechanism. 

Finding the right category to assign to a lexical item is possible because we 
make use of a goal directed parsing algorithm that avoids infinite ramifications of 
the search tree trying only those categories that are consistent with the context. 



2 A Parsing Algorithm Based on Lambek Calcnlus 



2.1 Lambek Calculus 

First, we introduce the Gentzen-style sequent formulation of LC. The underlying 
basic idea in the application of LC to natural language parsing is to assign a 
syntactic type (or category) to a lexical item. A concrete sequence of lexical items 
(words in some natural language) is grammatically acceptable if the sequent with 
these types as antecedent and the type s (sentence) as succedent is provable in 
LC. 

The language of the (product-free) LC for CG is defined by a set of basic 
or atomic categories (BASCAT) -also called primitive types-, from which we 
form complex categories -also called types- with the set of right and left division 
operators {/,\}: 

If A and B are categories, then A/B, and B\A are categories. 

We define a formula as being a category or a type. 

In the following we shall use lower case latin letters for basic categories, upper 
case latin letters for whatever categories, lower case greek letters for non-empty 
sequences of categories, and upper case greek letters for, possible empty, se- 
quences of categories. 

The rules of LC are [Lam58] : 

1. Axioms: 



2. Right Introduction: /R, \R 



■y,B^A B,'j ^ A 



3. Left Introduction: /L, \L 

7 i? r, A, A ^ C 
r,A/B,-f,A^ C ^ 



7 i? r, A, A ^ c 
r,j,B\A,A=^C ^ 



4. Cut 



7 A r, A, A ^ C 

r,j,A ^ c 



(Cut) 



It is required that each sequent has a non-empty antecedent and precisely one 
succedent category. The cut-rule is eliminable. 
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2.2 Automated Deduction in Lambek Calculus 

Given a lexicon for a natural language, the problem of determining the gram- 
matical correctness of a concrete sequence of lexical items (a parsing problem) 
becomes into a deductive problem in LC. Therefore, a parsing algorithm is just 
an LC theorem prover. 

LC-theoremhood is decidable. However, LC typically allows many distinct proofs 
of a given sequent that assign the same meaning; this problem is called ‘spurious 
ambiguity’. An efficient theorem prover has to search for (all) non-equivalent 
proofs only. There are in the literature two approaches to this problem, based 
on a normal form of proofs (Hepple [Hep90] , Konig, Moortgat [Moo90] , Hendriks 
[Hen93]) or on proof nets (Roorda [Roo91]). LC theorem prover we present is 
related to Konig’s method [K6n89], but it solves problems which are proper to 
Konig’s algorithm. 

First, we introduce some definitions. 

1. Value and Argument Formulae 

1.1. If F = a, then a is the value formula of F; 

1.2. If (i) F = G/ F[ or (ii) F = FI\G, then G is the value formula of F and 
F[ is the argument formula of F. In the case (i), F[ is the right argument 
formula; in the case (ii), F[ is the left argument formula. 

2. Value Path 

The value path of a complex formula F is the ordered set of formulae 
(Ai,... ,A„) such that A\ is the value formula of F and Aj is the value 
formula of Aj_i for 2 < j < n. 

3. Argument Path 

The argument path of a complex formula F is the ordered set of formulae 
{Bi,... ,Bn) such that B\ is the argument formula of F and Bj is the 
argument formula of Aj-i, for 2 < j < n, and {A\, . . . , A„) being the value 
path of F. 

The right (resp. left) argument path of a complex formula F is the ordered 
subset of its argument path owning right (resp. left) argument formulae only. 

4. Main Value Formula 

A is the main value formula of a complex formula F whose value path is 
(Ai, . . . , An) if and only if A = A„. 

It follows that: (i) if A is a main value formula, then A G BASCAT; (ii) 
every complex formula has exactly one main value formula. 



2.3 The Algorithm 

We now sketch the algorithm implemented in both C language and Prolog. We 
present the algorithm in a pseudo-Prolog fashion in order to provide an easier 
understanding. This is not Prolog, as we have simplified the management of data 
structures and other practical problems of the language. At the same time we 
assume a “try or fail” strategy of control like that of Prolog, as well as mechanisms 
of unification to build data structures. Self-evident procedures (search_value, 
etc.) are not included. 
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procedure proof 

data ^ target 

Proof tree if {h data target}, otherwise FAIL. 

data = target: RETURN 
target = A/B: RETURN 

target = B\A: RETURN rZi[^JlXT^\ \R)} 
atomic(target): 

LET c := target 

LET [listi, Ust 2 , ■ • ■ , Ustri\ := search .value (c in data) 

FOREACH listi G [listi, Ust 2 , ■ ■ ■ , listn] DO 
LET [a, F, (3] := listi 

LET [Ai, . . . , Ak] := left .argument .path (c in F) 

LET [Bi, . . . , Bm] ■= right.argument.path(c in F) 

LET treei := STACK reduce([ ],a, [A^, ■ ■ ■ , Ai]) 

WITH reduce([],/3, [Bi,... ,S„]) 

IF treCi = FAIL 
THEN CONTINUE 

ELSE RETURN { ° d^)} 

END FDR 
END procedure proof 

procedure reduce 

input: {[acums], [data], [targets]) 

output: proof tree if {\\-lc acums,data ^ targets}, otherwise FAIL, 

process ; 

CASE acums = data = targets = [ ]: RETURN { — (empty)} 

CASE targets = [A]: 

RETURN proof(acttms, data A) 

OTHERWISE: 

CASE acums ^ [] AND length(data) > length(tail(tar(/ets)): 

LET tree := STACK proof(ocMTOS head(tar 5 ets)) 

WITH redvLce{hea,d{data),ta,il{data),ta,il{targets)) 

IF tree ^ FAIL 

THEN RETURN tree 
ELSE try next case 

CASE length(tail(data)) > length(targets) - 1: 

RETURN redvLce{acums+hea,d{data),ta,il{data),tail{targets)) 
OTHERWISE RETURN FAIL 
END procedure reduce 

2.4 Remarks on the Algorithm 

(i) The proof procedure behaves as expected when input is an axiom. 

(ii) The algorithm decomposes any target complex formula until it has to prove 
an atomic one, c G BAS CAT. 



input ; 
output : 
process : 
CASE 
CASE 
CASE 
CASE 
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(iii) The reduce procedure is the main charasteristic of our algorithm. When we 
have to prove an atomic target, (i) we search for the formulae in the antecedent 
whose main value formula is the same as the atomic target {Fi, . . . , Fn); (ii) for 
each Fi,l < i < n, the left-hand side (resp. right-hand side) of the antecedent 
(with respect to Fi) and the left argument path of Fi (resp. right argument path) 
have to be cancelled out. The algorithm speeds up the deduction trying to satisfy 
the argument paths of Fi. The major advantages are obtained when the length of 
the sequence of data is long enough (note that a sentence in natural language may 
be up to 40 to 50 words long), and argument paths of the formulae are high. This 
property lies in the fact that the reduce procedure cares for still- not-consumed 
data and target formulae remaining to be proved. Efficient implementation for 
this algorithm has to avoid unnecessary calls to proof procedure from the reduce 
procedure, memorizing the proofs already tried. 

(iv) FAIL may be regarded as an error propagating value. If any of the arguments 
of the proof-tree constructors — such as STACK, (|l), (Jr), etc. — is FAIL, then 
resultant proof-tree is FAIL. A sensible implementation should be aware of this 
feature to stop the computational current step and to continue with the next 
one. 



2.5 Properties of the Algorithm 

(1) The algorithm is correct: If the output of proof procedure is not FAIL, then 
the proof tree constructed is a deduction of the input in LC. 

Proof. Every rule we employ is a direct LC rule: axiom, / R, \R. Note that the 
symbol \L stands for successive applications of /L and/or \L. The conditions 
needed for applying each rule are exactly the same as they are required in LC. 
Hence, we can construct a proof tree in LC from the output of the proof pro- 
cedure. □ 

(2) The algorithm is complete: If \~lc data target, then the output of the 
proof procedure is a proof tree. 

The proof follows from (2.1) and (2.2) below: 

(2.1) If there is no deduction in LC for ^,B => A, then there is no deduction in 
LC for 7 A/B. (Similarly for B,j ^ A, and 7 =7 B\A) 

Proof: Let us suppose that there is a proof tree, 77, in LC for 7 A/B. 
Case 1: If every rule in 77 is either a L-rule either an axiom, then we follow the 
deduction tree in a bottom-up fashion and we reach the sequent A/B A/B. 
We can construct a proof 77' from 77 in this way: 

B^B 

A I n n . A 



Next we apply the rules of 77 over A/B that yield 7 A/B in 77, and we obtain 
in 77': j,B A. 

Case 2: If there is an application of /R in 77 that yields 



6, B ^ A 
6^ A/B 



(/R) 
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but it is not at the bottom of 77, we can postpone the application of the /R rule 
in 77' till remaining rules of 77 have beeing applied, and so we have in 77' the 
sequent 7, 77 ^ A. □ 

We use these properties to decompose any complex succedent until we reach 
an atomic one. 

(2.2) Let c € BASCAT, and 7 = 71, . . . (n > 0). 

If 7 C) then it exists some jj, (1 < j < n) such that: 

(i) c is the main value formula of -jj; 

(ii) ll-LC 7i) • ■ • )7i-i ^ 

(iii) \'tlc 7j+i.--- ,7n ^ 

(iv) A deduction tree for 7 c can be reconstructed from (ii), (iii), and from 
the axiom c c. 

(Where (Ai,... ,Afc) is the left argument path of 7^-, <7 = (A^,... ,Ai), and 
A = (77i, . . . , Bm) is the right argument path of 7^). 

The symbol H-^c stands for the fact that a sequence of formulae (data) 
proves a sequence of target formulae keeping the order. If we consider the Lam- 
bek Calculus with the product operator, •, <7 and A can be constructed as the 
product of all Ai and all Bi respectively, and W-^c can be substituted for Llc 
in (ii), (iii). 

Note that (ii) and (iii) state that 71 ,... ,7j-i can be split up in k sequences 
of categories (ofc, ... , oi), and 7^+1 , ... ,7n can be split up in m sequences of 
categories (/3i, . . . , /3m) such that 
(ii') Oin ^ A„, for 1 < n < fc; 

(iii') l"LC Pn Bn, for 1 < n < TO. 

Proof: 

Ad (i) No rule except an axiom allows to introduce c in the succedent. Following 
the deduction tree in a bottom-up fashion, successive applications of /L and \L 
are such that (a) the argument formulae in the conclusion turn into the succe- 
dent of the premise on the left; (b) the value formula remains as part of the 
antecedent of the premise on the right; (c) the succedent of the conclusion re- 
mains as the succedent of the premise on the right — note that this ordering 
of the premises is always possible. Therefore we will reach the sequent c c 
eventually, being c the main value formula of jj . □ 

This property allows us to restrict, without loss of completeness, the application 
of the L-rules to complex formulae whose main value formula is the same as the 
(atomic) target succedent. 

Ad (ii) Let Flc 7 c. The only possibility of introducing A„ as a left argument 
formula of is from a L-rule. Hence, it exists some such that \~lc ctn ^ An, 
because of a„ A„ is the left-hand side premise of the L-rule. Otherwise, A„ 
together with c have to be introduced as an axiom, but the succedent is supposed 
to be an atomic type. 

Note that we can first apply all L-rules for (/), followed by all L-rules for (\) — or 
vice versa — , whatever the formula may be. That follows from the theorems: 
(a)hic {A\{B/D))/C^{{A\B)/D)IC 
{h)hLc{{A\B)/D)/C^ {A\{B/D))/C 
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(c) ^LC C\{{D\B)/A) ^ C\{D\{B/A)) 

(d) hic C\{D\{B/A)) ^ C\{{D\B)/A) □ 

Ad (iii) Similar to (ii). □ 

Ad (iv) Immediate from successive applications of /L and \L. □ 

(3) The algorithm stops. For whatever sequence of data and target, the number 
of tasks is finite, and every step simplifies the complexity of the data and/or the 
target. □ 

(4) The algorithm finds all different deduction and only once. 

If there are several formulae in 7 such that (i)-(iii) hold, each case corresponds 
to a non equivalent deduction of 7 c. 

The proof is based upon the fact that property (2.2) may be regarded as the 
construction of a proof-net for 7 c (in the equivalent fragment of non- 
commutative linear logic). The axiom c c becomes the construction of an 
axiom-link, and the points (ii) and (iii) become the construction of the corre- 
sponding sub-proof-nets with no overlap. Different axiom-links produce different 
proof-nets. □ 

3 An Abductive Mechanism for NLP 

We say a sequent is open if it has any unknown category instance in the an- 
tecedent and/or in the succedent; otherwise we say the sequent is closed. We use 
upper case latin letters from the end of the alphabet {X,Y,Z) for non-optional 
unknown categories, and X* , Y* , Z* for optional unknown categories. 

3.1 Learning and Discovery Processes 

We would consider two abductive mechanisms that we shall call learning and 
discovery processes, depending on the form of the target sequent. Discovery 
processes are related to tasks involving open sequents; learning processes are 
related to tasks involving closed sequents. 

1. Given a closed sequent, we may subdivide the possible tasks into: 

(a) Grammatical correctness: to check either or not a sequence of data yields 
a target, merely. This is the normal use of LG. 

(b) If a closed sequent is not provable, we can introduce a procedure for 
learning in two ways: according to data priority or according to target 
priority. 

i. If we have certainty about data, and a closed target is not prov- 
able from them, we remove the given target and we search for a 
(minimum) new target that may be provable from data. We need 
the target to be a minimum in order to avoid the infinite solutions 
produced by the type-raising rule. 

ii. If we have certainty about target, and the set of closed data does 
not prove it, we remove data, by means of re-typing the necessary 
lexical items, in such a way that the target becomes provable from 
these new data. 
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iii. If we have certainty about data and about target, we could consider 
the sequence as a linguistic phaenomenon that falls beyond a context 
free grammar, ellipsis, etc. 

In both cases (b.i) and (b.ii) we can appropriately say that we learn new 
syntactic uses. Moreover, in case (b.ii) we carry out a revision of the 
lexicon. 

2. An open sequent is related to discovery tasks. In a sense, every discovery 
task is also susceptible of being considered as a learning one (or vice versa) . 
However, we would rather prefer to differentiate them by pointing out that 
they are based on formal features of the sequents. 

3.2 The Abductive Mechanism 

The objectives we pointed out above need the parsing algorithm — hereafter, 
CC — to be enlarged using an abductive mechanism — hereafter, ACQ, Abduc- 
tive Categorial Grammar — for handling open sequents and removing types if 
necessary. ACQ manages: 

(i) input sequences either from corpora or users; 

(ii) information contained in the lexicon] 

(iii) data transfer to £C; 

(iv) input adaptation and/or modification, if necessary; 

(v) output of LC] 

(vi) request for a choice to the user; 

(vii) addition of new types to the lexicon — its update. 

What we have called an abductive mechanism has to do with the point (iv) 
most of all. We sketch only its main steps for taking into account the learning 
and discovery processes. Similarly to the parsing algorithm (2.3.), we present the 
procedure in a pseudo-prolog fashion. 

procedure learning 
input: {data ^ tar get) (A) 

such that ^ LC data ^ target, closed{data), closed{target) 
output: substitution {A := B} 

such that \~LC {data target){A := B} 
process : 

CASE certainty .about.target: 

LET [Ai , . . . , An] := data 
FOREACH Aj G [Ai, . . . , A„] DO 

LET new.data :=[..., Ai_i, Xi, A^+i, . . . ] 

{Xi := Bi} := discovering new-data target 
END FOR 

RETURN {Ai := Bi, . . . ,An ■■= H„} 

CASE certainty _about_data: 

{X := B} discovering data X 
RETURN {A := B} 

END procedure learning 
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procedure discovering 
input; {data ^ tar get) {X) 
output: {X := B} 

such that \~LC {data ^ target){X := B} 
process : 

CASE open_target: data => X 
IF data = [B] 

THEN RETURN {X := B} 

IF data = [Fi, . . . , F„] 

THEN FOREACH Fi{l<i<n), Fi ^ BAS CAT, DO 
LET Ci := search.value{Fi) 

{Y* := B^, Z* := C^} new.proof Y*,data, Z* a 
END FOR 

RETURN {Xi := Fi\ci/C'i, . . . , := F„\c„/C„} 

CASE open_data: data{X\, . . . , Xn) ^ target 

IF data = [AT] 

THEN RETURN {X := target} 

FOREACH Xi{l < i < n) DO 

LET [Fi,... ,F,_i,A:„F,+i,... ,F„] := data 
LET c := target 

LET new.data := [Fi, . . . ,Y*\cfZ*, . . . ,F„] 

{Xi := Bi\c/Ci} := new_proof new-data target 
END FOR 

RETURN [Xi := Fi\c/Ci, . . . , AT„ := F„\c/C„} 

END procedure discovering 

3.3 Remarks on ACQ 

The old proof procedure (2.3) has to be adapted to a new_proof one. To achieve 
this goal, we make two main changes: (a) the old proof procedure was built to 
work with closed sequents and now it should be able to deal with open ones; 
(b) the old proof procedure was initially designed to return a proof tree but it 
should now return the substitution that makes the open sequent provable. 

The old proof algorithm may work with open sequents, behaving as an ab- 
ductive mechanism, if we consider the (=) operator as unification. It is well 
known that the unification algorithm produces the substitution we are looking 
for. 

Two major changes come (a) from the search_value(c in data) procedure, 
and (b) from the reduce procedure. 

(a) The search_value procedure was considered to be self-evident, but now 
it needs further explanations inasmuch as unknown data or targets are present. 
What does it mean a value occurrence of X in Y? We will discuss the change in 
the process that considers a formula to be the main value of another one. 

procedure search_value 

input ; (Formula from data, target formula) 
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output: ([right_argument_path], target formula, [left -argument _path]) or FAIL 
CASE closed data (F) and closed target (c): 

CASE F = c: RETURN ([ ], c, [ ]) 

CASE F = B\A: RETURN {[B] + 7, c, (5) 

where (7,0, (5) := search_value(A, c) 

CASE F = A/B: RETURN (7, c, [B] + 6 ) 

where (7,0, (5) := search_value(A, c) 

OTHERWISE RETURN FAIL 
CASE closed data (F) and open target (AT): 

CASE F = c: RETURN X := c 
CASE F = B\A: RETURN STACK F 

WITH search_value(A, c) 

CASE F = A/B: RETURN STACK F 

WITH search_value(A, c) 

CASE open data (y) and closed target (c): RETURN ([ ],Y := c, [ ]) 
OTHERWISE RETURN FAIL 
end procedure search-value 



(b) Unknown categories may be either basic or complex ones. A treatment of 
the second case is rather difficult and it forces us to introduce constraints for 
bounding the search. We have to decide the upper bound of the complexity; 
i.e. X may be A\c/B, or Ai/A^/c/ Bi/ B2, etc. The reduce procedure requires 
some adaptations for working with optional categories. Optional categories are 
matched only if they are needed in the proof. 

CASE X* in target: 

IF data = [ ] 

THEN A* := [ ] 

ELSE A* := A 
CASE A* in data 
IF target = [ ] 

THEN A* := [ ] 

ELSE 

LET [Fi, . . . , A*, . . . , F„] := data 
IF proof [Fi, . . . , F„] target yf FAIL 
THEN A* := [ ] 

ELSE X*:= new-proof [Fi, ... , A, . . . , F„] target 

Finally, let us note that type-raising rules yield sequents like following: A => 
A/(A\A)orA=^ (A/A)\A — where A and A are whichever formulae — that are 
provable in LC. The basic (deductive) proof algorithm is complete and has no 
problem with the proof of such sequents, although some LC parsing algorithms in 
the literature (mainly natural deduction based ones) are not complete because 
of the type-raising rules are not provable in them. Regarding our new_proof 
algorithm, the problem arises when it works as an abductive process in which 
A, the target consequent, is unknown; then it may be regarded as atomic or as a 
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complex one. To regard it as atomic — our choice — causes no trouble but makes 
the type rising rule not provable (if the consequent is unknown). If we consider 
the possibility of an unknown consequent to be complex, then it may yield an 
endless loop. In fact, the type raising rule allows us to infer an endless number 
of more and more complex types. 

3.4 Running ACQ 

Example 1: 

Data: “John loves”. 

Initial state of the lexicon: 

John = np 

loves = np\s/np 

Sketch of the abductive process: 

(1) proof {np,np\s/np ^ s) = FAIL 

(2) Certainty about data: 

(2.1) np, np\s/np X 

(2.2) X := Y*\s/Z* 

(2.3) Y*,np, np\s/np, Z* ^ s 

(2.4) Y*,np ^ np-, Z* np 

(2.5) Y* := [ ]; Z* := np; X := sjnp 
Output: 

• John loves = s/np 

(3) Certainty about target: 

(3.1) X, np\s/np s 

(3.2) X := s/Y* 

(3.3) np\s/np Y* 

(3.4) Y* := np\s/np; X := s/{np\s/np) 

Output: 

• John = s/{np\s/np) 

(3.5) np, X ^ s 

(3.6) X := Y*\s/Z* 

(3.7) np,Y*\s/Z* ^ s 

(3.8) np^Y*; 

(3.9) Y* := np; Z* := [J 

(3.10) X := np\s 
Output: 

• loves = np\s 

(4) Certainty about data and target: 

Output: 

• John loves 2^ = np,np\s/np, np ^ s. 

Example 2: 

Data: “someone bores everyone” . 

Initial state of the lexicon: 
someone = ? (unknown) 
bores = np\s/np 
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everyone = ? (unknown) 

X, np\s/np, Z ^ s 

Sketch of the abductive process: 

(1) AT := s/Y*-, s/Y* ,np\s/np, Z ^ s 

(1.1) np\s/np, Z =>Y* 

(1.2) Y* := Y^*\s/Yi 

(1.3) Y{,np\slnp,Z,Y^ ^ s 

(1.4) 17 ^ np 

(1.5) Z,Y*^np 

(1.6) Fi* := np; Z := np; Y* := [ ] 

Output: 

• someone = s/{np\s) 

• everyone = np 

(2) X np; Z ^ np 

(2.1) X := np; Z := np 
Output: 

• someone = np 

(3) Z := F*\s; X, np\s/np, F*\s s 

(3.1) X,np\s/np^Y* 

(3.2) Y* := Y*\s/Y* 

(3.3) Yi , X,np\s/np,Y2 

(3.4) Y{,X ^ np 

(3.5) 17 ^ np 

(3.6) 17 := []; X := np; I 7 := np 
Output: 

• everyone = {s/np)\s 

State of the lexicon after runing ACQ: 
someone = np, s/{np\s) 
bores = np\s/np 
everyone = np, {s/np)\s 
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Abstract. We present a representation scheme for the declarative for- 
malization of strategies for action selection based on the situation calcu- 
lus and circumscription. The formalism is applied to represent a number 
of heuristics for moving blocks in order to solve planning problems in the 
blocks world. The formal model of a heuristic forward chaining planner, 
which can take advantage of declarative formalizations of strategies for 
action selection, is proposed. Experiments showing how the use of declar- 
ative representations of strategies for action selection allows a heuristic 
forward chaining planner to improve the performance of state of the art 
planning systems are described. 



1 Introduction 

Interesting research is being done lately on improving the performance of do- 
main independent planners using declarative representations of domain knowl- 
edge [1], [8], [24]. Domain knowledge can be represented in a number of different 
forms, such as task decomposition schemas [29], search control knowledge [1], 
or heuristics for action selection [25]. This paper builds on previous work on 
the declarative formalization of strategies for action selection [25] , describing its 
application to improving the performance of a forward chaining planner. 

The idea is to use heuristics for action selection (such as “if a block can be 
moved to final position^, this should be done right away”) to circumscribe the 
set of situations that should be considered by a planner to those situations that 
are selectable according to a strategy for action selection. We use a declarative 
formalization of strategies for action selection that allows refining the action 
selection strategy used by a planner (and, therefore, to prune its search space) 
by simple additions of better heuristics [19]. The incorporation of this idea to 
a forward chaining planner leads to the notion of a heuristic forward chaining 
planner, which can use declarative representations of action selection strategies 
to reduce considerably the size of its search space. We present the declarative 
formalization of an action selection strategy for the blocks world in section 4, 

^ In the blocks world, a block is in final position if it is on the table and it should be 
on the table in the goal configuration, or if it is on a block it should be on in the 
goal configuration and that block is in final position. 
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and we show how the planner can use this strategy for solving a number of blocks 
world problems. 

The paper is organized as follows. Section 2 presents a formal model of a sim- 
ple forward chaining planner. Section 3 introduces and formalizes the concept 
of a heuristic forward chaining planner, which can use declarative representa- 
tions of action selection strategies. Section 4 describes a representation scheme 
for the declarative formalization of action selection strategies proposed in [25]. 
Section 5 compares our approach to related work on the use of the declarative 
representations of domain knowledge for planning. Section 6 describes some ex- 
periments comparing the performance of our heuristic forward chaining planner 
and TLPlan [1]. Finally, section 7 summarizes our main contributions. 

2 Forward Chaining Planner 

We begin with the formal description of a forward chaining planner which ex- 
plores the space of possible situations, i.e., the set of situations generable by 
applying executable sequences of actions to the initial situation, until it finds a 
situation that satisfies the goal conditions. The planner uses a bounded depth 
first search strategy to explore the space of situations. 

The formal model of the forward chaining planner, presented below, is based 
on a formalization of STRIPS [5] in the situation calculus described in [21]. 
Associated with each situation is a database of propositions describing the state 
associated with that situation. The predicate DB{f, s) asserts that propositional 
fluent / is in the database associated with situation s. Each action is described by 
a precondition list, an add list, and a delete list, which are formally characterized 
by the following predicates: (1) Prec{f, a) is true provided proposition / is a 
precondition of action a; (2) Del{f,a) is true if proposition / becomes false 
when action a is performed; (3) Add{f,a) is true if proposition / becomes true 
when action a is performed. The function Result maps a situation s and an 
action a into the situation that results when action a is performed in situation 
s. When an action is considered, it is first determined whether its preconditions 
are satisfied (axiom 1). If the preconditions are met, then the sentences on the 
delete list are deleted from the database, and the sentences on the add list are 
added to it (axiom 2). 

We assume uniqueness of names for every function symbol, and every pair of 
distinct function symbols^. The constant symbols So and Sg denote, respectively, 
the initial and goal situations. The predicate Goal{s) is true provided situation s 
satisfies all the conditions that are true at the goal situation Sg . The expression 
s <r Si means that si can be reached from s performing a nonempty sequence 
of executable actions. We introduce an axiom of induction for situations that 
allows us to prove that a property holds for all the situations. This axiom also 
constrains the domain of situations to those that can be reached (<r) from the 
initial and goal situations [23]. 

^ The symbols h and g are meta-variables ranging over distinct function symbols; x 
and y denote tuples of variables. 
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The expression si <df S 2 is true provided situations si and S 2 can be both 
reached from So (or can be both reached from Sg), and situation si will be found 
earlier than situation S 2 if the tree of situations reachable from So (respectively, 
from Sg) is explored using a depth first search strategy {<aiph denotes the al- 
phabetic order). Finally, an action sequence p is the solution returned by the 
planner if the situation resulting from performing p in the initial situation sat- 
isfies the goal conditions and it is minimal with respect to the search strategy 
of the planner. The constant K is a natural number that corresponds to the 
maximum depth explored by the bounded depth first search strategy used by 
the planner. 

Poss{a, s) ^ \/f{Prec{f, a) DB{f, s)) (1) 

DB{f, Resultia, s)) ^ Possia, s) A [Add{f, a) V [DB{f, s) A -<Del{f, a))) (2) 

Vx,y(h(x) = h(y) ^ X = y); Vx,y(h(x) g(y)) (3) 

Goal(s) ^ yf(DB{f, Sg) ^ DB{f, s)) (4) 

Ss{-B <r So) /\Ss{-B <r Sg) ASa,S,Sl{s <r Result{a,si) <-> Poss{a,si) As <r Sl) (5) 
VP(P(5'o) A P(Sg) A Vs, a{P{s) A Poss{a, s) P{Result{a, s))) ysP(s)) (6) 
Si <df S 2 ^si <rS 2 'VJa,b,s{aSaiphbAResult{a, s) <rSiAResult{b, s) <r S 2 ) (7) 

Length(So) = 0 A Length(Sg) = 0 A Length{Result{a, s)) = 1-1- Length(s) (8) 
Ss{Result{[],s) = s) A Va,p, s{Result{[a\p], s) = Result{p, Result{a, s))) (9) 

Sol{p) 3s(s = Result{p, So) A So <r s A Goal{s) A Length{s) < KA (10) 
Vsi(So <r Si A Goal{s\) A Length{s) < K —> s <df si)) 

The axiom set Tpc = {1) • ■ • ) 10} is our formal model of a forward chaining 
planner. 

2.1 Blocks World Example 

We present now a formal model of the sort of information that must be commu- 
nicated to the forward chaining planner to solve a planning problem. This in- 
formation can be divided into domain dependent information (the precondition, 
add and delete lists of the available actions), and problem dependent information 
(the states associated with the initial and goal situations). 

The variables x, y and z range over blocks. The constants A, B, C, and T 
(for Table) are of the sort block. The function symbol On maps a pair of blocks x 
and y into the propositional fluent On{x, y) describing the fact that block x is on 
block y. The function symbol Clear maps a block x into the propositional fluent 
Clear{x) describing the fact that there is space on block x to place another block. 
We include a domain closure axiom for blocks. The initial and goal configurations 
are described by axioms 15 and 16. The function symbol Move maps a triple 
of blocks X, y and z into the action Move{x,y, z) denoting the act of moving 
block X from y to z. The precondition, delete and add lists of Move{x,y, z) are 
as follows. 

Prec{f, Move(x, y , z)) f = Clear (x)\/ f = On{x , y)\/{z^T —> f = Clear{z)) (11) 

Del{f, Move{x, y, z)) r-> f = On{x, y) V [z T —>■ f = Clear{z)) (12) 
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Add{f, Move{x, y, z)) ^ f = On{x, z)W {y ^ f = Clear{y)) (13) 

'ix(x = Ay X = B y X = C V X = T) (14) 

DB{f, So) ^ 3a;, y{{f = On{x, y) A {{x = A Ay = T) y {x = B A y = T)V (15) 

(x = C Ay = A))) V (/ = Clear{x) A {x = By x = C))) 
DB{f, Sg) 3a;, y{f = On{x, y) A ((a; = AAy = B)y{x = BAx = C)V (16) 

(x = CAy = T))) 

The axiom sets Tbwi = {Hj • • ■ j 13} and Tpi = {14, ... , 16} constitute our 
formal models of the blocks world domain and the problem known as Sussman’s 
anomaly, respectively. 

3 Heuristic Forward Chaining Planner 

A heuristic forward chaining planner is a forward chaining planner that explores 
the space of selectable situations, rather than the space of possible situations. 
Selectable situations are those that can be generated by applying sequences of 
selectable actions to the initial situation. A heuristic forward chaining planner 
needs information that goes beyond the classical specification of a planning prob- 
lem. In particular, it needs to know what actions are selectable at a particular 
situation. 

In the following section, we address the issue of how a user can specify such 
information. Let’s assume, for a moment, that the user supplies a definition of the 
predicate Sel{a, s), which is true provided action a can be selected at situation s, 
along with the specification of a planning problem. Then, the only modification 
that we need to make to the formal model of the forward chaining planner Tpc 
in order to obtain the formal model of the heuristic forward chaining planner 
Thfc is to replace the predicate Boss by the predicate Sel in axiom 5^. 

4 Declarative Formalization of Strategies for Action 
Selection 

In [25], we proposed a representation scheme for the declarative formalization 
of strategies for action selection based on the situation calculus [18] and circum- 
scription [20]. The idea is to represent strategies for action selection as sets of 
action selection rules [7]. An action selection rule is an implication whose an- 
tecedent is a formula of the situation calculus, and whose consequent can take 
one of the following forms: Good{a, s), Bad{a, s) or Better {a, b, s). The intuitive 
interpretation of these predicates is that performing action a at situation s is 
good, bad, or better than performing action b. 

The following action selection rules describe some heuristics for determining 
what blocks should be moved in order to solve planning problems in the blocks 

® This replacement redefines the reachability relation <r as follows: si <r S 2 is true 
provided S 2 can be reached from si by performing a sequence of selectable actions. 
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world: (1) If a block can be moved to final position, this should be done right 
away (axiom 17); (2) If a block is not in final position and cannot be moved to 
final position, it is better to move it to the table than anywhere else (axioms 18); 
(3) If a block is in final position, do not move it (axiom 19); ()) If a block is 
above another block it ought to be above but it is not in final position (i.e., it is 
in tower- deadlock position), put it on the table (axiom 20). 

-^Holds{Final{x),s) A Holds{On{x, y),s) A Holds{On{x, z), Sg) A (2 = TV (17) 
H olds{Final{z) , s)) A Poss{Move{x, y, z), s) —> Good(Move(x, y, z), s) 

-^H olds(Final{x) , s) A Holds{On{x, y),s) A Holds{On{x, z), Sg)A (18) 
{-^Holds{Final{z), s) V -<Poss{Move{x, y,z),s)) A w T 

Better {M ove{x , y, T), Move{x, y, w), s) 
Holds(On(x, y),s) A H olds{Final{x) , s) Bad{Move{x, y, z), s) (19) 

Holds{On{x, y),s) A Holds{TD{x),s) Good{Move{x, y, T), s) (20) 

The predicate Holds(fs) is true provided propositional fluent / is true at 
situation s. A block is in final position H olds{Final{x) , s) if it is on the table 
and it should be on the table in the goal configuration, or if it is on a block 
it should be on in the goal configuration and that block is in final position. A 
block is in tower- deadlock position H olds{T D{x) , s) if it is above another block 
it ought to be above but it is not in final position. Section 4.3 contains formal 
definitions of these symbols. 

A consistent set of action selection rules (such as S'! = {17, 18, 19, 20}) defines 
a strategy for action selection. 

4.1 Nonmonotonic Interpretation 

The formal semantics of a strategy for action selection Ts is given by INT{Ts) 
[25], the nested abnormality theory specified on the right hand side of formula 
22. Nested abnormality theories [16] extend simple abnormality theories [22] by 
allowing the specification of nested applications of the circumscription operator 
[20]. INT(Ts) characterizes the conditions under which an action is good or bad 
for a particular situation, by jumping to the conclusions that: (1) an action is 
“not good” unless the action selection rules in Tg imply that it is good; and (2) an 
action is “not bad” unless the action selection rules in Tg, together with axiom 
21, imply that it is bad. Axiom 21 asserts that an action is bad for a particular 
situation if there exists a better action for the same situation. 

Better{ai, 02, s) Bad(a2, s) (21) 

INT(Ts) = {Better, min Bad : 21, {min Good : Tg}} (22) 

Formally, this is achieved as follows. First, the predicate Good is circum- 
scribed with respect to the conjunction of the universal closures of the axioms 
in Tg. Then, the predicate Bad is circumscribed with respect to the result of the 
circumscription of Good in Tg and the universal closure of axiom 21. Better is 
allowed to vary because minimizing the extension of Bad may affect (through 
axiom 21) the extension of Better. 




138 



Josefina Sierra-Santibanez 



This nonmonotonic interpretation of action selection strategies has both rep- 
resentation and computational advantages. It allows describing strategies: (1) 
succinctly, since it is not necessary to specify negative information (i.e., which 
actions are not good, not bad, or not better than others); (2) according to a least 
commitment policy, in which it is not necessary to assert that an action is good, 
bad, or better than other unless it is known for sure; and (3) incrementally, since 
it is possible to refine an action selection strategy by simple additions of better 
heuristics (i.e., consistent action selection rules that may become available later 
on). In these three cases, circumscription takes care of appropriately adapting 
its consequences to the lack of information or the availability of new relevant 
facts. 

The following formal result establishes some conditions under which the in- 
terpretation INT{Ts) of a strategy for action selection Tg can be computed by 
a variant of Clark’s completion algorithm [4]. 

Proposition 1 If every axiom of T$ is a first order action selection rule such 
that its antecedent does not contain the predicates Good, Bad or Better, then 
INT{Ts) is equivalent to the conjunction of the first order sentences 23 and 24 
resulting from the application of the completion algorithm described bellow to 

Ts. 

'ia, s{Good{a, s) s)) (23) 

Va, s{Bad{a, s) s) V 3ai, 02(0 = «2 A «2, s))) (24) 



Completion Algorithm Let Tg be a declarative formalization of a strategy for 
action selection. The axioms of Tg are all of the form A — > P{ta,ts), where A is 
a first order formula which does not contain the predicates Good, Bad or Better, 
ta is a tuple of terms of the sort action, ts is a term of the sort situation, and P 
is one of the predicates Good, Bad or Better. 

Step 1 Replace each rule of the form A P{ta,tg) in Tg by Al A a = A s = 

ts P{oi, s), where a is a tuple of new variables of the sort action, and s is 
a new variable of the sort situation. 

Step 2 Replace each rule y4i(a, s) ^ P{a,s) obtained in the previous step by 
3xA\{a, s) — > P{a, s), where x are the free variables in the original rule. 
Step 3 For each P, replace all the rules of the form A\{a, s) ^ P{a,, s) obtained 
in step 2 by a single rule of the form Vi A\{a, s) ^ T(a, s). 

Step 4 Replace the rule A^°°'^{a, s) ^ Good{a, s) obtained in step 3 by 
Va, s(Good(a, s) ^ A|°°‘^(a, s)). 

Step 5 Replace the rules Al|“‘’*(a, s) ^ Bad{a,s) and ^ 3 ®“®’’(ai, 02 , s) ^ 
Better{ai, 02 , s) obtained in step 3 by a single rule^ of the form 
Va, s{Bad{a, s) ^ A^^'^{a, s) V 3ai, 02(0 = 02 A ^ 3 ®“®’’(ai, 02 , s))). 

^ We assume the variables a, ai and 02 of the sort action are distinct from each other. 
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Proof ( Proposition 1 ) The semantics of nested abnormality theories is charac- 
terized by a map that translates blocks® into sentences of a second order 
language. Proposition 1 in [16] allows us to describe the semantics of the nested 
abnormality theory INT{Ts) as the following circumscription formula®. 

(^{{Better, min Bad : 21, {min Good : Ts}}) = 

C1RC{21', CIRC{Ts\ Good)-, Bad-, Better) 

We use several rules for computing circumscription described in [15]. Formula 
(19) and proposition 2 in [15] allow us to prove the following equivalence. Formula 
23 is the first order characterization of the predicate Good obtained in step 4 
of the completion algorithm, Tsad is the conjunction of the universal closures 
of the action selection rules of the form A Bad{ta,ts) in Ts, and Tsetter is 
the conjunction of the universal closures of the action selection rules of the form 
A Better fta,ts) in Tg. 

GIRC(Ts-, Good) = 23 A Tsad A Tsetter 

The equivalence above, together with formula (19) and proposition 3 in [15] 
allow us to simplify INT{Ts) as follows. Tbetter is the second order formula 
obtained from Tsetter by substituting every instance of the predicate constant 
Better by a similar predicate variable better. 

CIRG{21', GIRC{Ts-, Good)- Bad-, Better) = 

GIRC{21', 23 A TBad A Tsetter; Bad-, Better) = 

23 AGIRC{TBad, 3better{2l' A Tbetter)-, Bad) 

Using equivalence (27) in section 3.2 of [15], we can prove that 3better{2l' A 
Tbetter) is equivalent to the following formula which does not depend on better. 

, 02 ,s), ai, 02 , a and s are as described in step 5 of the completion 
algorithm. 

Va, s(3oi, 02(0 = 02 A A 3 ®**®'’(oi, 02 , s)) ^ Bad{a, s)) (25) 

Finally, proposition 1 in [15] allows us to compute the result of circumscribing 
Tsad and 25 with respect to Bad. Formula 24 is the first order characterization 
of the predicate Bad obtained in step 5 of the completion algorithm. 

23 A GIRC{Tbad, 25; Bad) = 23 A 24 g 

For example, the nonmonotonic interpretation INT(Sl) of action selection 
strategy S'! (described by action selection rules 17 to 20) can be computed by 
the completion algorithm. We show the result of the last step of the algorithm. 

'ia,s(Good[a,s) ^3x,y,z{-Holds{Final{x),s) AHolds{On{x,y),s) AHolds{On{x,z),Sf)A 
{z = T y H olds(Final{z) , s)) A Poss{Move{x, y,z),s) A a — Move(x, y, z))V 
3x,y{Holds{On{x, y),s) A Holds{TD{x),s) A a = Move{x, y, T))) 

Va,s{Bad{a, s) ^ 3x,y,z(IIolds(On(x,y),s)AB'olds(Final(x),s)Aa — Move(x,y,z))V 
3ai,a2{a = a2A3x,y,z,w{-Bolds{Final{x),s)AHolds{On{x,y),s)AHolds{On{x,z),Sg)A 
{-^Holds{Final{z), s) V ^Poss{Move{x, y,z),s)) Aw A ai = Move{x, y, T)A 
fl 2 = Move{x,y,w)))) 



® Blocks are the equivalent of axioms in nested abnormality theories (see [16]). 
® In the following, we denote the universal closure of a formula Ahy A' . 
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These two formulas characterize the conditions under which a move is good 
or bad for a particular situation according to strategy for action selection SI. 



4.2 Mechanism for Action Selection 

The interpretation of an action selection strategy gives us a characterization of 
the conditions under which an action is good or bad for a particular situation. 
Suppose the user supplies, along with an action selection strategy, a theory of 
action that allows the planner to determine whether these conditions hold or not 
for a particular situation. Then, the planner could infer what actions are good 
or bad for every situation, and use that information to determine what actions 
should be selected. 

The following axiom characterizes the set of selectable actions for a particular 
situation. The predicate Poss(a, s) is true provided action a can be executed at 
situation s (axiom 1). 

Sel{a, s) ^ Poss{a, s) A {Good{a, s) V (^3bGood(b, s) A ~^Bad{a, s))) (26) 

According to the action selection mechanism described by axiom 26, an action 
is selectable at a particular situation if it is executable and good for that situation, 
or if there are no good actions for that situation and it is executable and not 
bad for that situation. 



4.3 Blocks World (Continuation) 

In order to interpret action selection rules, such as axioms 17 to 20, in terms of 
the theory of action described in section 2, we need to establish a connection 
between what holds at a situation and what is in the database associated with 
that situation. In this paper, we assume that the state associated with any 
situation can be described in terms of the truth values of a finite set of frame 
fluents [18] [14]. The rest of the fluents, called defined fluents, are described in 
terms of the frame fluents. The database associated with a situation determines 
the truth values of the frame fluents as follows: a frame fluent holds at a particular 
situation if and only if it is in the database associated with that situation. 

Frameif) ^ (Holdsif, s) ^ DB(f, s)) (27) 

The frame fluents for the blocks world are those of the form On{x, y) or 
Clear{x). In addition to frame fluents, we use a number of defined fluents, such 
as final, above^ , and tower-deadlock. 

^ If we assume uniqueness of names, a complete characterization of the predicate DB 
for the initial and goal situations, an axiom of induction for situations, and that there 
is only a finite number of blocks (as we do), the definitions of H olds{Final(x) , s) 
and Holds{Above{x,y),s) provided allow us to characterize the extensions of these 
formulas. 
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Frame{f) 3x,y{f = On{x,y) V / = Clear{x)) (28) 
Holds{Final{x), s) {F[olds{On{x, T),s) A Holds{On{x, T), Sg))\/ (29) 

3y{H olds{Final{y) , s) A Holds{On{x, y),s) A Holds{On{x, y), Sg)) 
FFolds{Above{x,y), s) <-> Holds{On{x,y),s) V 3z{Holds{On{x, z), s)/\ (30) 

Holds{Above{z, y), s)) 

Flolds{TD{x),s) -^H olds{Final{x) , s) A 3y{y / TA (31) 
Holds{Above{x,y), s) A Holds{Above{x,y), Sg)) 

Tbw = Tbwi U{27, • ■ • 31} is our extended theory of action for the blocks 
world. Let Tsi be the set of axioms INT(Sl) 1J{26} U Tbw- Tsi is a formal model 
of the action selection strategy for the blocks world described at the beginning of 
this section. We can use this axiom set to simulate the behavior of the heuristic 
forward chaining planner when it is given the description of Sussman’s anomaly 
problem Tpi along with the strategy for action selection Tsi- For example, if 
the constant K (maximum depth explored by the bounded depth first search 
strategy) is equal to 3, we can prove that the heuristic forward chaining planner 
only needs to explore 3 situations before finding the optimal solution (shown 
below) . 

Thfc U Tsi |J Tpi h Sol{{Move{A, C, T), Move{B, T, C),Move{A, T, B)}) 



Sel(a,S0) <=> Sel(a,Sl) <=> 

a=Move(C,A,T) a=Move(B,T,C) 



Sel(a,S2) <=> 
a=Move(A,T,B) 



c 

X 



B 




INITIAL SI 




Fig. 1. Heuristic forward chaining planner using action selection strategy S'! for 
solving Sussman’s anomaly problem. There is a single selectable action for every 
situation. 



The reason for which the planner only needs to explore three situations be- 
fore finding an optimal solution is the following. In the initial situation So, 
block C can be moved to final position. Action selection rule 17 implies that 
Move{C, A,T) is a good action. Blocks A and B are not in tower-deadlock po- 
sition and cannot be moved to final position, therefore there are no other good 
actions for the initial situation. Thus, the action selection mechanism (axiom 
26) implies that Move{C, A,T) is the only selectable action for So- 

Let Si be Result{Move{C, A, T), So)- Block B can be moved to final position 
in . The rest of the blocks are not in tower-deadlock position and cannot be 
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moved to final position. Therefore, Move{B,T,C) is the only good and thus 
selectable action for Si . 

Let S 2 be Result{{Move{C, A, T),Move{B, T, C)},S'o)- Block A can be moved 
to final position in 82 - The rest of the blocks are in final position. Therefore, 
Move{A,T, B) is the only selectable action for 32 - 

Re suit {{Move {C, A, T), Move{B, T, C), Move{A, T, B)}, Sq) is the first situ- 
ation found by the planner that satisfies the Goal predicate. Therefore, axiom 10 
implies that the action sequence {Move{C,A,T), Move{B,T,C), Move{A,T,B)} 
is the solution returned by the planner. 



5 Related Work 

Various techniques have been used to exploit domain knowledge for planning. 
HTN (hierarchical task network) planners [29] use domain knowledge in the form 
of task decomposition schemas which goes beyond the specification of precondi- 
tions and effects of actions used by classical planners. Domain knowledge has also 
been expressed in the form of search control knowledge. In particular, knowledge 
bases of forward chaining rules have been used to guide search. SOAR was the 
first system to use this approach [17], and a refined version of it is a prominent 
part of PRODIGY [28] . A similar rule-based approach to search control has also 
been incorporated into UCPOP [2]. The main disadvantage of the rule-based 
approach used by these systems is that their search control rules are specified 
in terms of implementation details of their planning algorithms. This is not the 
case for the action selection rules presented in this paper, which are expressed 
in terms of domain knowledge only. 

In [11], a problem solver guided by negative heuristics (which tell a system 
what not to do) is described. The heuristics are specified in PROLOG, and relate 
the goal to the current state and anticipated action. They are designed to elimi- 
nate actions which clearly do not contribute to the goal. Four negative heuristics 
for the blocks world, which eliminate part of the search and are subsumed by 
axiom 18 in this paper, are proposed. 

In [24], a forward chaining planner, which uses a regression based theorem 
prover and an iterative deepening search strategy, is proposed. The planner 
requires the following types of information from the user: (1) a predicate goal{s), 
which is true if situation s satisfies the conditions of the goal for which a plan 
is sought; (2) a set of action precondition and successor state axioms for the 
primitive actions of the domain; and (3) a predicate badSituation{s) , which is 
true if situation s is considered to be a bad situation for the planner to consider. 
The planner is implemented in GOLOG [13], and it has been extended to deal 
with concurrent actions and incomplete initial situations [6] . 

The representation scheme proposed in this paper is more expressive than 
those used in [11] and [24], in the sense that it allows the representation of positive 
heuristics (the predicate good tells a system what to do), and heuristics that 
establish preferences among actions (the predicate better establishes a partial 
order among actions). The predicate badSituation(s) allows pruning the search 
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space by characterizing those situations from which a successful plan cannot be 
reached, but it does not allow guiding the search in promising directions as the 
predicate good does in our formalization. 

The heuristics for the blocks world used in [6] prune approximately the same 
set of situations as action selection rules 17 to 19. In particular, the definition of 
good-tower is equivalent to our concept of final position. However, the heuristics 
in [6] do not consider the concept of tower- deadlock position, and therefore they 
cannot be used to discriminate between actions that move arbitrary blocks to 
the table (which are not necessarily optimal and can be postponed) and actions 
that move blocks in tower deadlock position to the table (which are necessary 
and should be executed right away). This is the meaning of action selection rule 
20. For example, the heuristics in [6] do not establish a preference between the 
actions M ovetotable(d) and M ovetotable{g) in the situation resulting from per- 
forming the sequence of actions {M ovetotable(pi),M ovetotable(p),M ovetotablelfi), 
M ovetotable(f)} in the initial situation of the problem described in [6]. How- 
ever, if action Movetotable(g) is chosen the resulting plan contains one ac- 
tion more than the optimal plan. Action selection rule 20 allows characterizing 
Movetotable{d) as a good action, because block d is in tower deadlock position, 
and M ovetotable(g) as a non bad action. 

Our planner has not been designed to solve planning problems with incom- 
plete initial situations. However, the declarative formalization of action selec- 
tion strategies proposed in this paper is adequate for dealing with open world 
planning problems [6]. For example, if we add the definitions of Final(x,s), 
Above(x,y,s) and TD(x,s) to the formalization of the blocks world presented 
in [6], action selection strategy = {32, ...,37} can be used for solving the 
open blocks world planning problem described in that paper®. 

-^Final{x, s) A On{x, y, Sg) A Final{y, s) —> Good{Move{x, y),s) (32) 

-^Finafix, s) A Ontable{x, Sg)/\ —> Good[Movetotable{x),s) (33) 

-^Final{x, s) A On{x, y, Sg) A {-^Final{y, s) V 3zOn{z, y, s)) (34) 

Better [M ovetotable{x) , M ove(x , w), s) 

Final{x,s) —> Bad{Move{x,y),s) (35) 

Final{x, s) Bad{Movetotable{x),s) (36) 

TD(x,s) Good{Movetotable{x), s) (37) 

In [1], a planning system called TLPlan, which uses first order linear temporal 
logic to represent search control knowledge, is described. This logic is interpreted 
over sequences of worlds. In particular, the goal and temporal modalities ((J until, 
□ always, O eventually, and Q next) are used to assert properties of world 
sequences. A search control formula describing the search control strategy to be 
used by the planner is specified by the user in this logic. This formula describes 

® Some other changes to the formalization in [6] are required as well. For exam- 
ple, the definition of the predicate Goal(s) should be replaced by Goal{s) ^ 
-i3xy{On{x,y, Sg) A ~^On{x,y,s)) A -<3x{Ontable{x, Sg) A ~^Ontable{x, s)). Axioms 
21, 26 and a new axiom describing the state associated with the goal situation Sg 
should be added as well. Space limitations do not allow a more detailed explanation. 
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properties the sequences of worlds generated by applying successful plans to the 
initial situation should satisfy. The planner uses a progression algorithm which 
serves as the basis for an incremental mechanism that allows checking whether 
a plan prefix, generated by forward chaining, could lead to a plan that satisfies 
the search control formula. Interesting experiments in which TLPlan is shown 
to perform better than state of the art planners, such as BlackBox [10], IPP 
[12], SatPlan [9], GraphPlan [3], PRODIGY [28] and UGPOP [2] in various test 
domains using search control formulas are described. 

TLPlan is an interesting example of a heuristic forward chaining planner, in 
which search control knowledge is expressed in terms of properties the sequences 
of worlds generated by selectable plans (rather than actions) must satisfy. The 
last search control formula used for the blocks world in [1] prunes approximately 
the same set of situations than the first three action selection rules of S'! (the 
action selection strategy proposed in section 4 of this paper) . In particular, their 
definition of good-tower is equivalent to our concept of final position. 

An advantage of our proposal is the availability of a formal model of the 
planner which allows limited forms of meta-reasoning, such as determining the 
correctness, redundancy, inconsistency or quality of different strategies for action 
selection. This is an important feature that may allow the planner to reject 
incorrect strategies, and to provide its users with feed back on how to improve 
their strategies. This is not possible in TLPLAN, because it does not have a 
formal description of its own mechanism for action selection which allows it to 
reason about the consequences of adopting a particular strategy. 

6 Experiments 

We have implemented a heuristic forward chaining planner which can use declar- 
ative representations of planning domains and strategies for action selection in 
Prolog. The planner has been applied to solve some blocks world problems using 
S'!, the strategy for action selection described in section 4. The first problem set 
(shown in table 1) consists of 10 randomly generated blocks world problems of 
25 blocks. The second problem set (shown in table 2) consists of 6 blocks world 
problems of different sizes. The sizes of the problems are specified in the first 
column of table 2. For each problem, we have computed the number of blocks 
that are initially in final and tower deadlock positions (columns Final and TD) . 

The numbers in the columns Steps, Nodes, and Time correspond to the num- 
ber of steps of the plans found by our planner, the number of situations (nodes) 
explored, and the time in milliseconds spent on planning. 

We have compared our results with those obtained from running the same 
problems in TLPlan. The numbers in the columns Steps TLPlan, Nodes TLPlan, 
and Time TLPlan correspond to the number of steps of the plans found by 
TLPlan, the number of situations (nodes) actually explored, and the time in 
milliseconds taken by TLPlan. 

In order to make a fair comparison, we have discounted one from the num- 
ber of nodes explored by TLPlan, because we do not count the initial situation. 
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It should be noted as well that we have used the domain definition and control 
strategy in Linear BlocksWorld.tlp (see http://www.uwaterloo.ca/~fbacchus). In 
this domain definition, the four actions {pickup(x), putdown(x), stack(x,y), un- 
stack(x,y)) are used to model the dynamics of the blocks world. We have used a 
single action Move(x,y,z), which corresponds to two TLPlan actions. Therefore, 
the plans obtained by TLPlan should be twice as long as ours, and the number of 
nodes explored 2n+ 1, where n is the number of nodes explored by our planner. 
The formulas we have used to compute the numbers shown in the columns Steps 
TLPlan and Nodes TLPlan are s/2 and {x — l)/2, respectively, where s is the 
number of steps of the plans found by TLPlan, and x is the number of nodes 
actually explored by TLPlan. 

Comparing the numbers in the columns Steps and Steps TLPlan, it can be 
observed that TLPlan cannot find optimal plans (i.e., with a minimum number 
of steps) for 10 of the 16 problems posed. Our planner obtains optimal plans for 
the 16 problems. As far as planning time is concerned, our planner is faster than 
TLPlan. The only exceptions are the problems of sizes 15 and 19. However, the 
numbers of steps of the plans found by TLPlan are very far from optimality, 18 
and 25 steps versus 14 and 18 steps for the optimal plans. 



Table 1. Problems of 25 blocks. 


Prob 


Final 


TD Steps Nodes 


Time 


Steps 

TLPlan 


Nodes 

TLPlan 


Time 

TLPlan 


1 


1 


2 


26 


26 


0 


26 


26 


58 


2 


0 


11 


36 


36 


0 


38 


38 


91 


3 


3 


1 


23 


23 


0 


25 


25 


58 


4 


7 


0 


18 


18 


0 


20 


20 


52 


5 


7 


2 


20 


20 


0 


20 


20 


46 


6 


1 


4 


28 


28 


0 


30 


30 


68 


7 


1 


6 


30 


30 


0 


37 


37 


91 


8 


1 


13 


37 


37 


0 


37 


37 


85 


9 


1 


3 


27 


27 


0 


29 


29 


68 


10 


1 


7 


31 


31 


50 


32 


32 


84 







Table 2. 


. Problems of different sizes. 




Size 


Final 


TD 


Steps Nodes 


Time 


Steps 

TLPlan 


Nodes 

TLPlan 


Time 

TLPlan 


5 


2 


0 






11 


0 


5 


5 


4 


13 


1 


3 




15 


15 


0 


15 


15 


19 


15 


2 


0 




14 


274 


320 


18 


18 


26 


19 


2 


0 




18 


3583 


5610 


25 


25 


47 


25 


5 


1 




22 


29 


50 


22 


22 


51 


50 


24 


0 




26 


26 


0 


26 


26 


158 



The specification of the problems, the strategy for action selection, the Prolog 
code of the planner and the log files with the results of the experiments can be 
obtained from the author (jsierra@ii.uam.es). 
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7 Conclusions 

We have studied the use of declarative representations of action selection strate- 
gies for planning. First, we have presented a representation scheme for the declar- 
ative formalization of strategies for action selection, which has a number of ad- 
vantages. One of these advantages is the possibility of defining positive heuristics 
which can guide the search process in promising directions. The compositionality 
of our declarative representation of strategies for action selection is an impor- 
tant feature as well, since it allows refining an action selection strategy by simple 
additions of better heuristics. 

Then, we have proposed a formal model of a heuristic forward chaining plan- 
ner, which can take advantage of declarative representations of strategies for 
action selection. The availability of such a formal model not only shows the fea- 
sibility of our idea from a theoretical point of view, it also allows interesting 
forms of meta-reasoning about declarative formalizations of strategies for action 
selection, such as: (1) determining the correctness of a particular strategy (or a 
class of strategies) with respect to a given domain; (2) updating and composing 
strategic knowledge from different sources; or (3) determining whether a set of 
heuristics improve, are inconsistent or redundant with a particular strategy for 
action selection. 

Finally, we have implemented a heuristic forward chaining planner in Prolog 
and run some experiments in order to determine whether this is indeed a practical 
idea. The experiments have shown that a heuristic forward chaining planner 
using declarative representations of strategies for action selection can improve 
the performance of state of the art planning systems, such as Blackbox, IPP or 
TLPlan. 
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Abstract. We consider an algorithmic approach for revising inconsis- 
tent data and restoring its consistency. This approach detects the 
“spoiled” part of the data (i.e., the set of assertions that cause incon- 
sistency), deletes it from the knowledge-base, and then draws classical 
conclusions from the “recovered” information. The essence of this ap- 
proach is its coherence with the original (possibly inconsistent) data: 
On one hand it is possible to draw classical conclusions from any data 
that is not related to the contradictory information, while on the other 
hand, the only inferences allowed by this approach are those that do not 
contradict any former conclusion. This method may therefore be used 
by systems that restore consistent information and are obliged to their 
resource of information. Common examples of this case are diagnostic 
procedures that analyse faulty components of malfunction devices, and 
database management systems that amalgamate distributed knowledge- 
bases. 



1 Motivation 

In this paper we introduce an algorithmic approach to revise inconsistent infor- 
mation and restore its consistency. This approach (sometimes called “coherent” 
[5], or “conservative” [15]) considers contradictory data as useless, and uses only 
a consistent part of the original information for making inferences. To see the 
rationality behind this approach consider, for instance, the following set of propo- 
sitional assertions: 

KB = {p, ~^p, -^pVq, r, ^rVs}. 

Since ^p is true in KB, so is ~^pVq (even if q is false), and so a plausible infer- 
ence mechanism should not apply here the Disjunctive Syllogism to p and q. 
Intuitively, this is so since the information regarding p is contradictory, and so 
one should not rely on it for drawing inferences. On the other hand, applying 
the Disjunctive Syllogism to {r, ^rVs} may be justified by the fact that this 
subset of formulae should not be affected by the inconsistency in KB, therefore 
inference rules that are classically valid can be applied to it. 

The two major goals of coherent approaches in general, and our formalism 
in particular, are therefore the following: 
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a) Detect and isolate “spoiled” parts of the knowledge-base, i.e.: Remove from 
the knowledge-base subsets of assertions that cause inconsistency, 

b) Draw classical conclusions in a non-trivial way from any data that is not 
related to the contradictory information. Such inferences should be seman- 
tically coherent with the original data, that is: Only inferences that do not 
contradict any previously drawn conclusions are allowed. 

For achieving the goals above we consider an algorithmic approach that is 
based on a four- valued semantics [3,4]. Using a multiple- valued semantics is 
a common way to overcome the shortcomings of classical calculus (see, e.g., 
[3,6,7,12,13,14]), and as we shall see in what follows, four- valued semantics is 
particularly suitable for our purpose. 

A similar algorithmic approach for recovering stratified knowledge-base, 
which is also based on a four- valued semantics, was introduced in [1,2]. Here 
we generalize and improve that approach in the sense that we consider a better 
search engine, and provide and algorithm that recovers arbitrary knowledge- 
bases rather than only stratified ones. 

2 Background 

2.1 Belnap Four- Valued Lattice 

Our method is based on Belnap’s well-known algebraic structure, introduced 
in [3,4]. This structure consists of four truth values: the classical ones (t, /), a 
truth value (_L) that intuitively represents lack of information, and a truth value 
(T) that may intuitively be understood as representing contradictions. These 
four elements are simultaneously ordered in two distributive lattices. In one of 
them, denoted by L 4 = ({t, /, T, T}, <t), f is the <i-minimal element, t is the 
<t-maximal one, and T,T are two intermediate values that are incomparable. 
The partial order of this lattice may be intuitively understood as representing 
differences in the amount of truth of each element. In the other lattice, denoted 
by A 4 = ({t, /, T, T}, <fe), T is the <fc-minimal element, T is the <fe-maximal 
one, and t, f are two intermediate values. The partial order <k of this lattice 
intuitively represents differences in the amount of knowledge (or information) 
that each element exhibits. We denote Belnap four-valued structure together 
with its two partial orders by TOUTZ (see Figure 1). 

As usual, we shall denote the <t-meet and the <t-join of TOU7Z by A and 
V, respectively. In addition, we shall denote by ^ the involution operation on 
<t, for which = T and ^T = T. 

2.2 Knowledge-Bases: Syntax and Semantics 

The language we use here is the standard propositional one, based on the propo- 
sitional constants t, /, T, T, and the connectives V, A, ^ that correspond, respec- 
tively, to the join, meet, and the negation operations w.r.t. <t. Atomic formulae 
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Fig. 1. Belnap lattice, TOUTZ 



are denoted by p, g, literals (i.e., atomic formulae or their negations) are denoted 
by I, and complex formulae are denoted by Tp,(j). Given a set S of formulae, we 
shall write ^(S') to denote the set of the atomic formulae that occur in S, and 
jO{S) to denote the set of the literals that occur in S {A and £ denote, respec- 
tively, the set of atomic formulae and the set of literals in the language). The 
complement of a literal I is denoted by 1. An atomic formula p G .4(5') is called 
a positive (negative) fact of 5 if pG 5 {~^pG S). The set of all the (positive and 
negative) facts in S is denoted by Facts{S). 

The various semantic notions are defined on TOIATZ as natural generaliza- 
tions of similar classical ones: A valuation u is a, function that assigns a truth 
value in TOIATZ to each atomic formula. Any valuation is extended to complex 
formulae in the obvious way. The set of the four- valued valuations is denoted by 
V. A valuation v satisfies ip iff v{ip) G {t, T}. t and T are called the designated 
elements of TOUTZ. A valuation that satisfies every formula in a given set 5 of 
formulae is a model of 5. A model of 5 will usually be denoted by M or N. The 
set of all the models of 5 is denoted by mod{S). 

The formulae that will be considered here are clauses, i.e.: disjunctions of 
literals. The following useful property of clauses is easily shown by an induction 
on the structure of clauses: 

Lemma 1. Let ip he a clause and v a valuation. Then v{ip) G{t,T) iff there is 
some lG£{ip) s.t. v{l)G{t,T}. 

A finite set of clauses is called a knowledge-base, and is denoted by KB. 
As the following lemma shows, representing formulae in a clause form does not 
reduce the generality. 
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Lemma 2. [1] For every formula ip there is a finite set S of clauses such that 
for every valuation v, v{ip) G {T, t} iff v{(p) € {T, t} for every <pGS. 

Given a certain knowledge-base KB, we consider the <fe-minimal elements in 
mod{KB). These models reflect the intuition that one should not assume what 
is not really represented in KB. 

Definition 1. Let ui,i' 2 GV. 

a) vi is k-smaller than V 2 iff for every atom p, vi{p) <k ^ 2 {p)- 

b) V Gmod{KB) is a k-minimal model of KB if there is no other model of KB 
that is fc-smaller than v. 



Example 1. Consider the following knowledge-base: 

K.B = {p, ^q, ^p\J q, ^p\J h, g V r V s, q\J ^r\J ^s, h\J r, hV s\ 

The (^-minimal) models of KB are given in Table 1 below. We shall use KB for 
the demonstrations in the sequel. 

The fc-minimal models of KB will have an important role in the recovery 
process of KB. This may be justified by the fact that as long as one keeps 
the amount of information as minimal as possible, the tendency of getting into 
conflicts decreases. 

2.3 Recovered Knowledge-Bases 

Definition 2. Let vGV. Denote: I{v) = {pGA \ i^{p) = T}. Usually we shall be 
interested in the assignments of v w.r.t. a specific knowledge-base. In such cases 
we shall consider the following set: I{v,KB) = {pGA{KB) \ v{p) = T}. 

As we have noted above, by “recovering a knowledge-base” we mean to turn 
it (in a plausible way) to a consistent one. That is: 

Definition 3. A valuation v is consistent if I{v) = %. A knowledge-base is con- 
sistent if it has a consistent model. 

Proposition 1. [1,2] A knowledge-base is consistent iff it is classically consis- 
tent. 

The recovery process is based on the following notion: 

Definition 4. A recovered knowledge-base KB' of a knowledge-base KB is a 
subset of KB with a consistent model M' s.t. there is a (not necessarily consis- 
tent) model M of KB, for which M' (p) = M (p) for every pGA(KB'). 
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Table 1. The (fc- minimal) models of KB 



Model No. 


P 


q 


h 


r 


s 


fc- minimal 


Ml 


t 


T 


t 


_L 


_L 


+ 


M2 ~ Af/4 


t 


T 


t 


_L 


/,t,T 




Ms - Mi6 


t 


T 


t 


/,t,T 


T,/,t,T 




Miy ~ M ^2 


t 


T 


T 


T,/,t,T 


T,/,t,T 




M33 


T 


/ 


_L 


t 


T 


-f 


M34 


T 


/ 


_L 


T 


t 


-f 


M35 


T 


/ 


_L 


T 


T 




M36 


T 


/ 


/ 


t 


T 




M37 - M38 


T 


/ 


/ 


T 


t,T 




M39 


T 


/ 


t 


_L 


T 


-f 


M40 


T 


/ 


t 


/ 


t 


-f 


M41 


T 


/ 


t 


/ 


T 




M42 


T 


/ 


t 


t 


/ 


-f 


M43 


T 


/ 


t 


t 


T 




Af/44 


T 


/ 


t 


T 


_L 


-f 


M45 - M47 


T 


/ 


t 


T 


/,t,T 




M48 


T 


/ 


T 


_L 


T 




M49 - M50 


T 


/ 


T 


/ 


t,T 




M51 - M52 


T 


/ 


T 


t 


/,T 




M53 - Ms6 


T 


/ 


T 


T 


T,/,t,T 




M57 


T 


T 


_L 


t 


t 


-f 


Ms8 


T 


T 


_L 


t 


T 




M59 - Meo 


T 


T 


_L 


T 


t,T 




Mei - Me 4 


T 


T 


/ 


t,T 


t,T 




Mbs - Mso 


T 


T 


t 




T,/,t,T 




Msi - M96 


T 


T 


T 




T,/,t,T 





Example 2 . The set {p} is a recovered knowledge-base of KBi = {p, q, ~^q}, but it 
is not a recovered knowledge-base of KB2 = {p, ~^p}- This example demonstrates 
the fact that in order to recover a given inconsistent knowledge-base, it is not 
sufficient to find some of its (maximal) consistent subset (s), but it is necessary 
to ensure that the subset under consideration would semantically correspond 
to the original, inconsistent data; In our case, {p} does not recover KB2 even 
though it is a classically consistent subset of KB2, just because of the fact that 
this set contradicts an information ffip) that is explicitly stated in the origi- 
nal knowledge-base. Therefore, the “semantical correspondence” property is not 
preserved in this case.^ 



^ Keeping this “semantical correspondence” to the original information is one of the 
main differences between the present formalism and some other formalisms for restor- 
ing consistency (see, e.g., [ 5 , 6 , 9 ]). 
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Given an inconsistent knowledge-base KB, the idea is to choose one of its re- 
covered knowledge-bases and to treat this set as the relevant knowledge-base for 
deducing classical inferences. Next we show that the set of recovered knowledge- 
bases of KB may be easily constructed from the set of its models: 

Definition 5. Let v&V. The set that is associated with v is defined as follows: 

KBy = {'ip^KB I v{ip)=t and A{ip) n I{v, KB) = tb}. 

The set KBy corresponds to the (maximal) fragment of KB that can be inter- 
preted in a consistent way by v. Elimination of pieces of “inadequate” informa- 
tion in order to get a more “robust” representation of the “intended” knowledge 
is a common method in belief revision and argumentative reasoning (see, e.g., 
[5,6,9]). 

Proposition 2. [1] Every set that is associated with a model of KB is a recov- 
ered knowledge-base of KB. 

Proposition 2 implies that usually there will be a lot of ways to recover a given 
inconsistent knowledge-base. By what we have noted above, plausible candidates 
of being the “best” recovered knowledge-base of KB would be those sets that 
are associated with some fc- minimal model of KB.^ 

Definition 6. A set S C KB is a preferred recovered knowledge-base of KB if 
it is a maximal set that is associated with some /c-minimal model of KB. 



Example 3. Consider again the knowledge-base ICB of Example 1 . In the nota- 
tions of Table 1, the subsets of KB that are associated with its fc- minimal models 
are the following: 

KB Ml = {p, ~^py h, h\J r, ft, Vs}, 

KBm33 = {^9) h V r|, 

KBm34 = {^9) h V s|, 

KBm 39 = {^9, h V r|, 

A, 8 m 4 o = q'dT'ds, g V V ^s, ft V r, ft Vs}, 

KBMi 9 = {^q^ qMrMs, g V V ^s, ft V r, ft Vs}, 

KBmu = {^g, h V s}, 

KBmzj = {ft V r, ft V s}. 

Thus, the preferred recovered knowledge-bases are KBmi and KBm 4 o=^^M 42 - 

3 Recovery of Inconsistent Knowledge-Bases 

In this section we introduce an algorithm for recovering inconsistent knowledge- 
bases, and consider some of its properties. 

^ See [2] for some other preference criteria for choosing recovered knowledge-base. 
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Definition 7. Let KB be a knowledge-base, and let be a four-valued partial 
valuation defined on (a subset of) A{KB). The dilution of KB w.r.t. i' (notation: 
KB J, v) is constructed from KB by the following transformations: 

1. Deleting every 'tpGKB that contains either t, T, or a literal I s.t. v{l) S {t, T }, 

2. Removing from every formula that remains in KB every occurrence of /, _L, 
and every occurrence of a literal I such that iy{l) G {/, _L}. 

The intuition behind the dilution process resembles, in a way, that of the 
Gelfond-Lifschitz transformation [8]: Any data that has no effect on the rest 
of the process is eliminated. Thus, for instance, if a literal I in a formula i/' is 
assigned a designated value, then Lemma 1 assures that eventually i/' would also 
have a designated value, no matter what would be the values of the elements in 
£(^/>) \ {?}. Hence, these elements can be disregarded in the rest of the construc- 
tion, as indeed indicated by item (1) of Definition 7. The rationality behind item 
(2) of the same definition is similar. 

Figure 2 contains a pseudo-code of the recovery algorithm. ^ ^ As we show 
in Theorems 1 and 2 below, given a certain knowledge-base KB as an input, the 
algorithm provides the valuations needed for constructing the preferred recovered 
knowledge-bases of KB. 

It is easy to verify that the algorithm indeed halts for every knowledge-base. 
This is so since knowledge-bases are finite, and since for every set S of clauses 
and every partial valuation i' on ^(S'), we have that ^(5 J, C^(S'). 

Example 4- Figure 3 below demonstrates the execution of the algorithm on the 
knowledge-base ICB of the canonical example (1 and 3). In this figure we denote 
by p:a: the fact that an atom p is assigned a value x. 

In the notations of Table 1, the two leftmost paths in the tree of Figure 3 
produce the /c-minimal model Mi, and the other paths produce the fc- minimal 
models M40 and M42.® As noted in Example 3, these are exactly the models 
with whom the preferred recovered knowledge-bases of ICB are associated. By 
Theorem 2, these are all the preferred recovered knowledge-bases of ICB. 



Proposition 3. Let be a four-valued valuation produced by the algorithm of 

Figure 2 for a given knowledge-base KB. Then ly is a model of KB. 

Proof: Let ip C KB. By Definition 7 and the specifications of the algorithm in 

Figure 2, it is obvious that at some stage of the algorithm ip is eliminated from 

® The first parameter of the first call to Recover is the dilution of KB w.r.t. the empty 
valuation. This is so in order to take care of the propositional constants that appear 
in KB (for instance, if p V / € KB then p £ KB f 0) . 

^ If the knowledge-base under consideration contains clauses that are logically equiv- 
alent to / or T (e.g., /VT), then in KB f 0 such clauses will become empty. One 
can easily handle such degenerated cases by adding to the algorithm a line that 
terminates its execution once an empty clause is detected. 

® Later on we shall take care of the redundancy. 




An Algorithmic Approach to Recover Inconsistent Knowledge-Bases 155 



the set of clauses as a result of a dilution on this set. Note that a formula cannot 
be eliminated by successively removing every literal of it according to condition 
(2) of Definition 7, since the last literal that remains must be assigned a des- 
ignated value. Thus there must be some I G C{tp) that is assigned a designated 
value. By Lemma 1, then, {t, T}, and so u^mod{KB). □ 



input: A knowledge-base KB. 

Mods = Recover (KBf0, 0); 
do (VM G Mods) { 

KBm = {V>G KB I ^3p GGl(KB) such that M(p) =T}; 
output (KB h) ; 

} 

procedure Recover (S,i^) 

/* S = a finite set of clauses, v = the valuation constructed so far */ 

{ 

if (S == 0) then return (i^) /* is a fc-minimal model of KB */ 

pos = {p GGl(S) I p G S }; /* the positive facts in S */ 

neg = {p GGl(S) I ^p G S }; /* the negative facts in S */ 

if (pos U neg == 0) { 
do (Vp Gyf(S)) { 
pick p; 

if (p GH(S)) then Recover (S U {p} , v) 
if (^p GH(S)) then Recover(S U {^p}, v) 

} 

} 

do (Vp G (pos n neg) ) { 
pick p; 

)i(p) = T; 

S' = S f /r; 

do (Vq 7 ^ p such that q G Vl(S) \ Vl(S')) 

/i(q) = _L; 

Recover(S', v U jj.) ; 

} 

do (Vp G (pos U neg) \ (pos n neg)) { 
pick p; 

if (p G pos) then /i(p) = t else /i(p) = /; 

S' = S f /r; 

do (Vq 7 ^ p such that q G Vl(S) \ Vl(S')) 

/i(q) = _L; 

Recover(S', v U jj.) ; 

} 

} 



Fig. 2. An algorithm for recovering knowledge-bases 
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Fig. 3. Execution of the algorithm w.r.t. the canonical example 



The next proposition indicates that the valuations produced by the algorithm 
of Figure 2 assign designated truth values only to a minimal amount of literals 
(no more literals than what is really necessary for providing a model for KB). In 
a sense, this means that a minimal amount of knowledge (or belief) is assumed. 



Proposition 4. Let v he a, four-valued valuation produced by the algorithm of 
Figure 2 for a given knowledge-base KB. Then v \s a choice function on KB: 
For every ipGKB there is exactly one literal lGC{if) s.t. v{l) is designated. 
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Proof: The proof is by an easy inspection on the execution of the algorithm. 
Consider some ip € KB. Suppose that it is eliminated at the z-th inductive call 
to Recover. Then all the literals lGC{ip) for which v{l) is defined until the z-th 
recursive call to Recover has the property that v(l) = f (otherwise ip would have 
already been eliminated). Then there is some I € C(ip) (which is chosen during 
the z-th execution of Recover), for which v{V) G {t, T}, and after the next dilu- 
tion Ip is eliminated, i.e.: all the rest of the literals in C{ip) are assigned T. It 
follows, then, that every clause has a unique literal that is assigned a designated 
value by z^. □ 

Here is another evidence to the fact that only a minimal knowledge is assumed 
by the valuations produced by our algorithm: 

Theorem 1. Let zz be a four- valued valuation produced by the algorithm of 
Figure 2 for a given knowledge-base KB. Then z/ is a fc-minimal model of KB. 

Proof: First, by Proposition 3, z/ is a model of KB. It remains to show, then, 
that zz is a k -minimal among the models of KB. For that consider the following 
set of knowledge-bases: 

KBo = KB liP, KB,+i = KB, i ly, 

where Vi (z > 0) is the partial valuation determined during the z-th recursive 
call to Recover.® Now, let us first assume that there is at least one (positive or 
negative) fact in KB (i.e., there is a literal IgC{KB) s.t. IgKB). We show that 
z/ is a fc-minimal model of KB by an induction on the number n of the recursive 
calls to Recover that are required for creating v. 

— n = 0: vq may assign T only to a literal I s.t. IgKB and IgKB, while all the 
other elements in A{KB) are assigned T. In this case T is the only possible 
value for I, and so v is /c-minimal. The same argument is true for any literal 
I s.t. IgKB and l^KB (for that I, v{l) = t). It is also obviously true for all 
the literals that are assigned T. 

— rz > 1: Let M be a model of KB. We show that M yjfc v. Let Mi be the 

reduction of M to A{KBi), and suppose first that Mi is a model of KBi. By 
the induction hypothesis vi is a fc- minimal model of KBi, thus there exists 
p&A{KBi), s.t. Mi(p) zzi(p), therefore M<Pk’^- The other possibility is 
that Ml is not a model of KBi . In this case there must be a clause ipi G KBi 
s.t. Miiipi) ^ {t, T}. Since M is a model of KB, then by Lemma 1 there is 
a, Ip G KB and an I G C{ip) s.t. M{1) G {t, T}, and {?} U C{ipi) C C{ip). But 
then v{l) ^{t, T} (Otherwise, ip is eliminated in the dilution of KB and so 
ipi ^KBi), while M{1) G {t, T }. It follows that M{1) therefore M 

in this case also. 

To conclude, it remains to handle the case where there are no facts in KB. 
In this case our algorithm operates on KB' = KBGi{l} for some I G C{KB). 

® Thus, if the algorithm terminates after n recursive calls to Recover, then z^ = |J(Lj Vi. 
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But now there is a fact in KB' , and so by what we have shown above our al- 
gorithm produces a fc- minimal model for KB' . Denote this model by v' . We 
have to show that v' is also a fc- minimal model of KB. Indeed, v' is clearly a 
model of KB. Let M be some other model of KB. If M{1) G {t, T} then M is 
a model of KB' and so M -ftk v' ■ Otherwise, M(J) G {/, _L}. Consider the subset 
of formulae of KB in which I appears as a literal: KB{1) = G KB \ IgC{iI^)}. 
Since I G C{KB), it follows that KB (I) ^ 0. Moreover, since we assume that 
there are no facts in iLB, in particular I ^ KB and KB, thus KB {I) 

Now, by the definition of v' as a valuation that is produced by our algorithm, 
for every p G A(KB(l)) s.t. p^l, we have that v'{p) = _L. (Such p exist since 
KB{l)^% and KB{l)(^{l,l}. These atoms are assigned _L since all the formulae 
in KB{l) are removed after the first dilution of KB'). Now, since we assumed 
that M{l) G {/, _L}, then by Lemma 1 there must exist some po G A{KB{1)) 
s.t. M{po) G{t,T} (Otherwise ytpGKB{l) M{ip) ^{t,T} and so M cannot be a 
model of KB ) . Thus M{po)>k A = A (po) and once again we have that M -^k A . □ 

Using Theorem 1 we can now show that the algorithm indeed properly re- 
covers inconsistent knowledge-bases. 

Theorem 2. For a given knowledge-base KB, the algorithm of Figure 2 pro- 
duces all the valuations ly, for which KBi, is a preferred recovered knowledge-base 
of KB. 

Proof: By Theorem 1, if is obtained by our algorithm, then KBi, is an element 
of the following set: 

f2 = {KBm I M is a fc- minimal model of KB}. 

It remains to show, therefore, that the algorithm produces valuations zy,-, for 
which are the maximal elements of 17. Indeed, given a fc-minimal model 

M of KB, we show that the algorithm produces a valuation v s.t. I{v,KB) C 
I{M,KB), and therefore KBm ffiKBi,. 

As in Theorem 1, we denote by i^i the partial valuation that is determined 
during stage i of the algorithm (thus, if the algorithm terminates after n stages, 
then ly = and Mi is the reduction of M to the literals on which Vi is 

defined. Also, we use the following notations: KBq = KB [%, and for every z>0, 
KBi+i = KBi i Now, suppose first that Facts(KBo) yf 0 (i.e., there is some 
[positive or negative] fact in KBq). If {1,1} C Facts {KB q) for some literal I, set 
iyo{l) = T (note that in this case necessarily M{l) = T as well, since M is a model 
of KB and so it must assign T to all the facts of KB that are both positive and 
negative). Otherwise, choose some I G Facts(KBo) s.t. M{l) = t (such a literal 
must exist, since M is a model of KB and so it must assign designated values to 
the facts of KBq), and set V(j{l) = t. If Facts(KBo) is empty, then if there is some 
IgC{KBq) s.t. M{l) = t set iyo{l)=t as well. Otherwise, pick some IgC{KBq) 
s.t. M{1) = 1. and set vo{l) = t (there must be such a literal, since otherwise 
\/IgC{KBo) M{l)G{T,f} and since Facts{KBo) = tb, this implies that M is not 
fc-minimal, since one can easily construct a model of KB which is fc-smaller than 
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M by changing one of the /-assignments of M to _L, or one of the T -assignments 
of M to t). Now, in order to determine v\ we follow a similar procedure, this time 
for KBi'. If Facts(KBi) then if {ij} C Facts(KBi) for some I, set iyi{l) = T 
(note that in this case necessarily M{1) = T as well, since by the construction 
of r'o, we have that KBi = KB J, r'o ^ KB J, Mg, and so {1, 1} C KB J, Mg as well, 
which means that M must assign I the value T in order to be a model of KB). 
Otherwise, if there is some I G Facts(KBi) s.t. M{1) = t set = t as well. 
Otherwise, pick some iGFacts(KBi) s.t. M{1)g± (again, such an I must exists. 
Otherwise, by the same reasons considered above, we will have a contradiction 
to the fact that M is a fc- minimal model of KB), and set vi{l) = t. The procedure 
in case that Facts{KBi) = ^ is the same as the one in case that Facts{KBo) = ^. 
Now, repeat the same process until for some n, KBn becomes empty. Let 
= The following two facts are easily verified: 

1. In the process of creating v we followed the execution of the algorithm along 
one path of its search tree. Hence is obtained by our algorithm when KB 
is given as its input. 

2. If iy{l) = T then M{l) = T as well (see the notes whenever i^i{l) = T). 

By (2), I(v,KB)CI[M,KB), and so KBmQKB,^. Thus, by (1), an output v of 
the algorithm corresponds to a preferred recovered knowledge-base KB,y of KB. 
□ 



Clearly, large knowledge-bases that contain a lot of contradictory information 
may be recovered in many different ways. Therefore, computing all the preferred 
recovered knowledge-bases in such cases might require a considerable amount 
of running time. It is worth noting, however, that arbitrary recovery of a given 
knowledge-base KB (i.e., producing some preferred recovered knowledge-base of 
KB) obtains quite easily. This is so since the execution time for producing the 
first output (valuation) is bounded by 0{\£{KB)\ ■ \KB\); A construction of the 
first output requires no more than \C(KB)\ calls to Recover (as there are no 
more than \£{KB)\ picked literals), and each call takes no more than 0{\KB\) 
running time. 

We conclude this section with some notes on practical ways to reduce the 
execution time of the algorithm. 

A. Pruning of the Search Tree 

Let us consider once again the search tree of Figure 3. Denote the paths in this 
tree from the leftmost righthand by 1, . . . , 12. Clearly, paths 1 and 2 yield the 
same result. Similarly, the same valuation is produced in paths 3,6,7,11,12, and 
the remaining paths in the search tree also yield the same valuation. It is possible 
to avoid such duplications by performing a backtracking once we find out that 
we are constructing a valuation which is the same as another valuation that has 
already been produced before. Indeed, note that a path i in the search three of 
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the algorithm corresponds to a sequence of partial valuations ... that 

are constructed along its nodes. Thus, if we denote by A{KB)[^\ the elements of 
A{KB) on which the partial valuation fj. is defined, then it is possible to terminate 
the j-th flow of the algorithm (terminology: to prune the j-th subtree) at stage 
TO iff there is a flow i<j, s.t. IJfcLi = IJfeLi 

Example 5. In Figure 3 the pruning locations (in paths 2, 5-12) are marked with 
an asterisk. Thus, only paths 1, 3, and 4 of the search tree are not pruned. They 
yield, respectively, the /c-minimal models Mi, M 42 , and M 40 of ICB."^ 

Obviously, the pruning consideration might drastically improve the search 
mechanism of the algorithm. The tradeoff is that for checking the pruning con- 
dition we have to use much more memory space, since the algorithm has to keep 
tracks to valuations that correspond to previous search flows. 



B. Handling Unrelated Information 

There are many cases in which a new information should not affect any previous 
conclusion.® In such cases a plausible mechanism of belief revision should not re- 
tract any previous conclusion. Therefore, the general expectation is that in these 
cases the computational complexity of adding the new data to the knowledge- 
base and computing its new consequences would be relatively low. Detecting 
those cases and finding an appropriate methodology to handle them is sometime 
called “the irrelevance problem” . In the next proposition we show that in cases 
where a totally irrelevant information arrives, it is possible to avoid executing the 
recovery algorithm; The new data can safely be added to any preferred recovered 
knowledge-base without damaging any of its properties. 

Proposition 5. Let KBi and KB 2 be two subsets of a knowledge-base KB that 
satisfy the following conditions: 

(a) KBi U KB 2 = KB, (b) A{KBi) n A{KB 2 ) = ^,^ (c) KBi is consistent. 

If S' is a preferred recovered knowledge-base of KB 2 , then SUKBi is a preferred 
recovered knowledge-base of KB. 

Proof: For the proof we need the following result: 

Lemma 5- A: [1,2] For every model M of a knowledge-base KB there is a k- 
minimal model M' of KB s.t. M' <k M 

^ As noted in Example 3, these are exactly the models with whom the prefered recov- 
ered knowledge-bases of ICB are associated. 

® This is the case, for instance, where there is no evidence of any relation between the 
new data and the old one. 

® In case that conditions (a) and (b) are satisfied we say that KBi and KB 2 are a 
partition of KB. 

This property is sometimes called smoothness [10] or stopperdness [11]. 
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Suppose now that S' is a preferred recovered knowledge-base of KB 2 - Then it is 
associated with some ^-minimal model V 2 of KB 2 , i.e. S= {KB 2 )u 2 - Also, since 
KBi is classically consistent, it has a classical model, denote it Now, consider 
a valuation v that is defined for every atomic formula p as follows: 






1^1 (p) ifpeA{KBi) 
V2{p) \ip&A{KB2) 



Since A{KBi) n A{KB2) = 0, is well defined. It is also easy to see that is a 
model of KB, and that KB,, = {KB2) v^^iKBi) = SUKBi. By Lemma 5-A there 
is a /c-minimal model M of KB s.t. M <k v. In particular, I (M, KB) C I {y, KB), 
and so KB„ C KBm- But KB„ = S' U KB\, and since S is a maximal recovered 
knowledge-base of KB 2 , KB,, must be a maximal recovered knowledge-base of 
KB. Thus KBm = KB„ = S U KB\ is a maximal recovered knowledge-base of KB 
and it is associated with a fc- minimal model of KB. Hence S U KB\ is indeed a 
preferred recovered knowledge-base of KB. □ 



Note that an immediate consequence of Proposition 5 is that in case that 
KB is classically consistent, then KB itself is the (only) preferred recovered 
knowledge-base, as indeed one expects. 

Example 6. Consider again our canonical example (1, 3, 4). Let ICB' = K-B U 
{m, ->uVw}. The prefered recovered knowledge-bases of K-B are simply obtained 
by adding {u, ->uVw} to each prefered recovered knowledge-base of KB. I.e., the 
preferred recovered knowledge-bases of are {p, ^p\Jh, h\Jr, hVs, u, ~^v\/w} 
and {^< 7 , g V r V s, g V V ^s, h V r, h V s, u, ^v\/w}. 

It follows that in many cases it is possible to drastically reduce the execution 
time of the algorithm: If the knowledge-base under consideration can be parti- 
tioned into two subsets such that one of them is classically consistent, then in 
order to recover the knowledge-base it is sufficient to activate the algorithm only 
on the inconsistent subset, and then to add the consistent set to every preferred 
recovered knowledge-base that is obtained by the algorithm. 



4 Conclusion 

In this work we have introduced a simple algorithmic method for restoring the 
consistency of inconsistent knowledge-bases. Restoration of consistent data is 
a key concept in many applications, such as model-base diagnostic systems, 
database management systems for distributed (and possibly contradicting) 
sources of information, and pre-processing phases of procedures for a (classi- 
cal) automated deduction. In all these areas, then, the techniques discusses in 
this paper may be useful. 

We have addressed here the propositional case in which our algorithm can 
easily be implemented in practice. Its computational complexity in the general 
case, and further practical considerations for an efficient handling of first-order 
languages, remain to be studied. 
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Abstract. In the belief change literature, while the degree of belief (or disbelief) 
plays a crucial role, it is assumed that potential hypotheses that have neither been 
accepted nor rejected cannot be compared with each other in any meaningful 
manner. We start with the assumption that such hypotheses can be non-trivially 
compared with respect to their plausibility and argue that a comprehensive theory 
of acceptance should take into account the degree of beliefs (or disbeliefs) as well 
as the plausibility of such tenable hypotheses. After showing that such a compre- 
hensive theory of acceptance based on the received principle of minimal change 
does not lend itself to iterated acceptance, we propose, examine and provide rep- 
resentation results for an alternative theory based on the principle of rejecting the 
worst that can handle repeated acceptance of evidence. 



1 Introduction 

The theory of belief change, originating in the classic works [AGM85, Gar88] (hence- 
forth the AGM Theory) takes into account what we may term the degree or firmness of 
currently held beliefs. The basic idea that these theories rest on is that in assimilating 
new information, a rational agent should see to it that if some currently held beliefs must 
be given up, then, given the option, less firmly held beliefs may be given up in favour of 
more firmly held beliefs. Possibility theory [DP92], on the other hand, heavily relies on 
what may be termed as the degree of disbelief. The basic idea behind possibility theory 
is that in assimilating new information, a rational agent may be forced to suspend disbe- 
lief in some sentences that are currently disbelieved (i.e., their negations are believed); 
and in such an eventuality the agent should see to it that given the option, the suspension 
of disbelief is carried out with respect to less strongly denounced propositions instead of 
more strongly denounced propositions. In fact, both these approaches — belief change 
and possibility theory — are largely inter-translatable since the firmness of the belief in 
a sentence may be viewed simply as the strength of denouncement with respect to its 
negation. 

Since each sentence is either believed or disbelieved or neither, given an agent’s 
belief state, sentences of a language may be partitioned into three disjoint cells, namely, 
beliefs (sentences that the agents takes to be true in her model of the world), disbeliefs 
(sentences that the agent takes to be false in her model of the world) and plausibilities 
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(sentences that the agent is agnostic about). The measure used by the belief change 
camp, exemplified by, for instance, epistemic entrenchment, is primarily defined over 
the beliefs. The measure used by the possibility theory camp (the possibility measure), 
on the other hand, is primarily defined over the disbeliefs. More to the point, both these 
measures effectively refuse to compare different plausibilities. This is rather ironic since 
both these camps are rather recent entrants to the state-updating area compared to the 
Bayesian tradition which is primarily based on the probability of the plausibilities.' 

It is perhaps a mistake to consider the Bayesian approach and the belief change 
(or, for that matter, possibility theory) as competitors: they are best viewed as comple- 
menting each other in providing us a model for the general task of accepting some new 
evidence. Belief change and possibility theory primarily provide a model for accepting 
new information that conflicts with the current knowledge. This problem has come to be 
known as revision in the literature. The account they give of accepting new information 
that is not in conflict with the current knowledge may be viewed as a special case that 
should not be taken seriously. Similarly, the Bayesian tradition may be taken as provid- 
ing us a model of how to accept evidence that is consistent with the current knowledge. 
This problem has come to be known as expansion. Bayesian doctrine is more up-front 
about its treatment of evidence that conflicts with the current knowledge - the Bayesian 
doctrine is not designed to handle such evidence. 

In light of the above discussion, it is apparent that a general account of acceptance 
should provide a non-trivial account of handling two types of evidence - disbeliefs and 
plausibilities - in the sense that it should be based on a measure that allows non-trivial 
comparison among beliefs (or disbeliefs) and among plausibilities. This purported ac- 
count of acceptance may be quantitative in the Bayesian style or qualitative in the AGM 
style. The purpose of this paper is to provide a qualitative account of such a general the- 
ory of acceptance. 

This account should satisfy certain high-level desiderata that will be explicated in 
more detail in the next section: 

1. The theory of acceptance in question should allow the non-trivial comparison of 
beliefs (mutatis mutandis disbeliefs) on the basis of their strength or firmness, 

2. The theory of acceptance in question should allow the non-trivial comparison of 
hypotheses that have neither been accepted nor rejected on the basis of their plau- 
sibility, 

3. The construction of the purported acceptance operation should be based on ratio- 
nally defensible principles 

4. The properties of the purported acceptance operation should be intuitively appeal- 
ing, and finally, 

5. The framework used for this construction should allow for an iterated account of 
acceptance in a non-trivial manner. 

The rest of this paper is organised as follows. In the next section, I show that when we 
impose comparability among plausibilities on the AGM framework, we get an opera- 
tion (to be called “acceptance”) that behaves like revision or abduction depending on 

* In the Bayesian framework, each beliefs receive probability 1 and each disbelief gets probabil- 
ity 0. So there is no non-trivial comparison among beliefs (or disbeliefs). Only the comparison 
among the plausibilities is nontrivial. 
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the nature of the received evidence. In the section following it, I discuss and examine 
the limited nature of this operation, namely that it cannot process sequential pieces of 
evidence in a satisfactory manner. In the penultimate section, an alternative theory of 
acceptance based on the principle of rejecting the worst is presented, and its proper- 
ties examined. Appropriate representation results are presented in this section. Finally I 
conclude with a brief discussion of how this proposed theory lends itself to an account 
of iterated acceptance of evidence. 



2 Comparison among Plausibilities: Genesis of Abduction 

In the introductory section, I argued that a theory of acceptance should take into account 
comparison among plausibilities, that is among sentences that are neither believed nor 
disbelieved by an agent. In this section, I will postulate such a comparison among plau- 
sibilities and show that this leads to an account of abduction or inference to the best 
explanation [Pau93] of the variety propounded by Pagnucco in [Pag96]. I will then ex- 
plain how this theory of abduction can be used in a theory of acceptance and point out 
one of its severe limitations, namely that this account does not lend itself to an iterated 
account of acceptance. 

The comparison among plausibilities will be modelled after the comparison among 
the beliefs as provided by the relation of epistemic entrenchment [GM88]. Hence I will 
first provide a brief introduction to the classic account of belief change [AGM85] fol- 
lowed by a semantic account of epistemic entrenchment [Gro88]. After that I will give 
an analogous account of comparison among plausibilities that will lead to Pagnucco’s 
account of abduction [Pag96]. 



2.1 Belief Change 

In the AGM system, a belief state is represented as a theory or belief set (i.e., a set of 
sentences closed under your favourite consequence operation), new information (epis- 
temic input) is represented as a single sentence, and a state transition function, called 
revision, returns a new belief state given an old belief state and an epistemic input. If the 
input in question is not belief contravening, i.e., does not conflict with the given belief 
state (theory), then the new belief state is simply the consequence closure of the old 
state together with the epistemic input. In the other case, i.e., when the input is belief 
contravening, the model utilises a selection mechanism (e.g. an epistemic entrenchment 
relation over beliefs, a nearness relation over worlds or a preference relation over theo- 
ries) in order to determine what portion of the old belief state has to be discarded before 
the input is incorporated into it. 

From here onwards 1 will assume a finitary propositional object language C? Let 
its logic be represented by a classical logical consequence operation Cn. The yielding 
relation h is defined via Cn as: L h a iff a G Cn{r). 

^ A finitary language is a language generated from a finite number of atomic sentences. So the 
number of sentences in this language is not finite. 
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The AGM revision operation is required to satisfy the following rationality postu- 
lates: Let AT be a belief set (a set of sentences closed under Cn), the sentence a; € £ be 
the evidence, * the revision operator, and K* the result of revising K by x. 

(1*) AT* is a theory 

( 2 *) x&Kl 

(3*) Kl C Cn{K U {x}) 

(4*) If a: ^ then Cn{K U {a;}) C AT* 

(5*) a:* = A:_l iffh ^a; 

(6*) If h a; ^ y, then AT* = K* 

(7*) C Cn{Kl U {y}) 

(8*) If -y ^ K* then Cn{K* U {y}) C 

Motivation for these postulates can be found in [Gar88]. Let us call any revision op- 
eration that satisfies the above eight constraints “AGM rational”. These postulates can 
actually be translated into constraints on a non-monotonic inference relation [GM94] . 

The account of belief change provided here is non-constructive. A popular construc- 
tion of the revision operation * is obtained via the relation < of epistemic entrenchment. 
This relation < is a binary relation defined over the language C and the expression 
a; < y is meant to be read off as: sentence y is no less firmly believed than the sentence 
X. The standard conditions that < is meant to satisfy can be found in [Gar88]. The op- 
eration * can be constructed via < in the following manner: an arbitrary sentence y 
is in K* just in case either y is implied by x or {x ^ ^y) < {x ^ y). The principal 
(second) case, means that, when, relative to the evidence x, the information in ^y is less 
firmly held than the information in y, the sentence y should be accepted on the basis of 
evidence x. Instead of giving details of epistemic entrenchment, I will now provide its 
semantics, supplemented by visual aid, which has obvious intuitive appeal. 

2.2 Semantics of Entrenchment 

The semantics of epistemic entrenchment is given by what has come to be known as the 
“Systems of Spheres” (SOS), originally developed by Adam Grove [Gro88]. The one I 
will present is different in approach, but is equivalent to the construction propounded by 
Grove. Let A4 be the class of maximally consistent sets w of sentences in the language 
in question. The reader is encouraged to think of these maximal sets as worlds, models 
or scenarios. I will use the following expressions interchangeably: “w |= a”, “a allows 
w” and “w G [a]”, where w is an element in A4 and a is either a sentence or a set 
of sentences.) Given the belief set AT, denote by [A"] the worlds allowed by it, i.e., 
[K] = {w G f4 \ K Q w}. (Similarly, for any sentence x, let \x] be the set of “worlds” 
in which x holds.) 

A system of spheres is simply represented by a connected, transitive and reflexive 
relation (total preorder) C over the set A4 such that [AT] is exactly the set of C -minimal 
worlds of A4. Intuitively, w G w' may be read as: w is at least as good/preferable as w' 
(or, w' is not strictly preferred to w)? 

^ Note the oddity: the C-minimal world is most preferred. This is a legacy from the literature. 
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The relation C nicely captures the idea behind epistemic entrenchment: x < y for 
an agent just in case, from that agent’s perspective, the most preferred ^x-world is no 
less preferred than the most preferred ^y-world. More formally, x < y if f w^x E w^y 
where w^x is a C-minimal ^x-world and w^y is a C-minimal ^y-world. In intuitive 
terms, x is less firmly believed that y just in case it is easier for one to move from one’s 
current perspective to a ^x-scenario than to a ^y-scenario. It is easily verified that non- 
beliefs, in particular plausibilities (sentences that allow some but not all [IT] -worlds) 
are all < equivalent, and hence < cannot discriminate among plausibilities. The reason 
for this is that, given two plausibilities x and y, the worlds that are C-minimal in [^a;] 
and those that are C-minimal in [^y], being members of [K], are C-minimal worlds. 

Now, we define the Grove-revision function G* as: = {w G [a;] | for all w' G 

[a;],w E w'}, whereby K'^* = turns out that the AGM revision pos- 

tulates characterise the Grove revision operation G*."* A visual representation of the 




Fig. 1. Minimality Based revision - the principal case 



crucial case in the Grove Construction is given in Figure 1 . In this, the area marked [a;] 
represents the models allowed by the evidence x. The area \K] represents the model 
currently entertained by the agent, and the broken circles demarcate models according 
to the agent’s preference. The farther a model is from the centre, the less preferred it 
is. The shaded part of [a:] represents the most preferred of the models allowed by the 
evidence x - hence identified with [AT*]. 

Viewed from this semantic angle, belief change is about preferential choice: [K^*\ 
essentially identifies the subset to be chosen from [a;] as the set of worlds that are C-best 
in [a:]. 

We introduce the following notation for later use. 



Readers acquainted with Grove’s work will easily notice that given a system of spheres E, the 
relation can be generated as: w Qs w' iff for every sphere S' that has w' as a member, 
there exists sphere S S' with w as a member. On the other hand, given a total preorder C on 
At, a system of spheres E\z can be generated as follows: A set <S C At is a sphere in E\z iff 
given any member w of <S, ifw'Qw then w' is also a member of S. It is easily noticed that the 
□-minimal worlds of At constitute the central sphere, and for any sentence x, the □-minimal 
members of [®] constitute [K^*] in the corresponding SOS. 
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Definition 1 A subset T of A4 is said to be \f-flat just in case w C w' for all members 
w,w' ofT. In this case, the members ofT are called -equivalent, w IZ w' , on the 
other hand, is used as an abbreviation for (w C w') A {w' % w) 

2.3 Minimality Based Abduction 

Earlier I argued that like beliefs and disbeliefs, plausibilities too can be meaningfully 
compared with each other. We also noticed that epistemic entrenchment does not pro- 
vide a meaningful comparison among plausibilities since all the worlds validating the 
agent’s current knowledge (namely members of [K]) are C-minimal. In order to effect 
a non-trivial comparison among the plausibilities, therefore, it seems prudent to intro- 
duce some more structure into [K], Let us accordingly give up the assumption that [K] 
is the set of C-minimal worlds, and instead impose the following conditions: 

1. [K\ 0 and 

2. If w C w' and vJ G \K] then w G \K], for every w, w' in AA. 

In effect, the system of sphere represented by C represents an expectation ordering 
[GM94]. The belief state [K] in this system of spheres could be any of the sphere in 
the system. Grove’s SOS is a special case of this, namely when [K] is the smallest 
sphere allowed by Cl - i.e., \K] is the set of C-minimal worlds. Another special case 
is when [K] = A4. This represents the knowledge state of an epistemically innocent 
agent who does not know anything about the world. But a more interesting special case 
is the dual of Grove’s SOS: \K] = {w|w is not C-maximal}. In other words, whereas 
in Grove’s account, \K] is E-flat, in this dual account, AA \ \K] is E-flat. If we assume 
a binary relation A over £ defined as: x y iff w^x E w^y where w^x is a IE- 
minimal ^x-world and w^y is a E-minimal ^y-world, we get a relational measure that 
effectively compares plausibilities, but fails to discriminate among beliefs (and among 
disbeliefs). This is the mechanism that drives Pagnucco’s account of abductive belief 
change [Pag96]. 

Analogous to the AGM approach to revision, expansion in Pagnucco’s approach 
rests on minimality consideration. Given evidence x which is consistent with the current 
knowledge, the result of adopting x is represented by the new belief state \Kf] = 
{w I w is E -minimal in [a;]} = {w | w is E -minimal in [AT] n [x]}. However, since 
\K] is not necessarily E-flat, neither is [K] n \x\. Hence, possibly \Kf] C [K] n [a;]. 
Thus, unlike the expansion in the AGM approach, Pagnucco’s expansion operation -f 
is ampliative. In fact this operation has all the hall marks of an abductive inference. 
Figure 2 provides a visual representation of the abductive process suggested in [Pag96] . 

Pagnucco has examined the properties of this abduction operation. Let K be the cur- 
rent belief set, x the evidence and -f the abductive expansion operation. The following 
list fully characterises this operation. 

(1+) AT+ is a theory 

(2+) \f^x^K then x € Kf 

(3+) KQKf 

(4+) If a: h then K+ = K 

(5+) If AT 1/ ^a; then ^x ^ Kf 
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[K] 

[x] 

[K+x] 



Fig. 2. Minimality based Abduction 



(b'*') If K \- X ^ y, then AT+ = Ky 
(7+) K+ C C'n(if+v,) U {a;}) 

( 8 +) 

The motivation behind these properties can be found in [Pag96]. 



3 Minimality Based Acceptance and Its Failure 

In the last section I showed how the desire for comparision of plausibilities, combined 
with the minimality based belief change, leads to Pagnucco’s account of abduction. 
In this section I will combine the AGM approach to belief change with Pagnucco’s 
account of abduction in order to provide a comprehensive account of acceptance. Then 
I will show that this approach suffers from a serious setback in that it does not lend itself 
to an account of iterated acceptance. The next section will be devoted to an analysis of 
this problem of iteration, and a solution to this problem will be presented. Later on, 
technical exploration based on this suggestion will be performed. 



3.1 Acceptance Based on Minimality 

In the last section, we dispensed with the AGM idea that the belief state \K] is the 
smallest sphere in an SOS and assumed that \K] could be any sphere in the SOS. I 
pointed out that the AGM system (read Grove’s SOS) is one special case of this, and 
Pagnucco’s system is another special case. Now, we can combine these two accounts to 
offer a general account of acceptance. Roughly, what we wish the acceptance operation 
to do is to behave like the AGM operation when the evidence is belief contravening, 
and behave like the Pagnucco operator when the evidence is consistent with the current 
beliefs. Let us denote this minimality based acceptance operator as © and define this 
operation 0, given an expectation ordering C and an appropriate belief set K as follows: 
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Definition 2 (from C to ©) Where be a total preorder on M. and [K] a sphere for 
Q, [K®] is defined as the set {w & [x] | w C w' for all w' € [a;]}. 

It is easily verified that when the evidence x conflicts with K, the operation © behaves 
like the AGM revision operator; on the other hand, if x is consistent with K, instead 
of behaving like the AGM revision operator, the operation © starts behaving like Pag- 
nucco’s abductive expansion operator. This process may be visually represented as in 
Figure 3. 




3.2 Acceptance Faces the Iteration Problem 

Iteration has been a well known problem in the belief change literature. Formally, a 
function /, in order to be iterative, simply requires that if f{x) is a well defined ob- 
ject, then so should be f{f{x)). In the context of belief change, failure of the iterative 
property means an agent is guaranteed an initial change of mind, but not necessarily 
any subsequent one. Since in practice agents do not get all pieces of evidence in one 
go, it is highly desirable that any belief change operation, acceptance included, should 
have the iterative property. In the belief change lingo, it means that the belief change 
operation should satisfy the properties of category matching: the object that undergoes 
change must result in an object of the same category. 

Unfortunately, however, the acceptance operation © seriously fails on this count. 
There are different ways of looking at this problem. Primarily, a structured object i\K], 
which consists of possibly many layers of ©-equivalence classes of worlds) undergoes 
an epistemic change in response to evidence x and results in an unstructured object 
([Ff®], which is a single class of ©-equivalent worlds). Hence operation © violates the 
principle of category matching.^ 

^ Perhaps a more accurate description of the problem is the following. There are three arguments 
to 0: an expectation ordering ©, an arbitrary sphere [K\ of © and the evidential (external) input 
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The practical problem is noticed very easily. Consider Figure 3. Imagine that a and 
(3 are two pieces of evidence such that \K] n [a] 7 ^ 0 and [K®] n [/?] 7 ^ 0. Assuming 
that [K] n [a] is not C-flat, the first operation of © will result in an abductive expansion. 
Now, in order to process evidence (3 we will need a system of sphere in which [AT®] 
is a sphere. But since [Ff®] is C-flat, given the measure C, no matter how we permute 
the ©-equivalent classes, if [AT®] is going to be a sphere in the resultant SOS, it is 
going to be the central sphere. Hence we are back to a Grovian SOS, and all future 
expansions are going to be the non-abductive AGM expansion. Another way of looking 
at it is that although the desirability of a nontrivial comparison among plausibilities led 
to the theory of acceptance at issue here, after the first abduction, we are left only with 
a vacuous comparison among plausibilities. 

3.3 Diagnosis and Prescription 

It is clear from discussion above that iteration is desirable in the context of acceptance, 
and the operation © fails on this count primarily because [A"®] consists of a set of ©- 
equivalent worlds, in particular, the set of ©-minimal a;-worlds. This has often been 
justified on the basis of the principle of minimality (read minimal change). Hence, in 
order that we may gain the ability to iterate, it is imperative to satisfy the principle 
of category matching. This in turn implies that we impose more structure into the set 
[A"®], and thereby violate the principle of minimality. In this context, it is important to 
take into consideration a few issues: 

1 . What is the intuitive justification for the principle of minimality? 

2. Our proposal to impose more structure into [A"®] and thereby violate the princi- 
ple of minimality is based on purely pragmatic ground. Can this be justified on 
independent grounds? 

3. The discussion in the last section regarding the failure of iteration in the context of 
acceptance is primarily based on abduction. Is it possibly desirable to violate the 
principle of minimality only in the context of abduction and retain in the context of 
revision? 

I will address these issues individually. 

As to the first issue, the principle of minimality in question is essentially based on 
the intuitively obvious principle of choosing the best [NF98]. In order to successfully 
accept the evidence x, the result [A'®] is required to be a subset of [x]. Hence, it is a 
matter of choosing the “right” elements of [x\. Since © reflects the agent’s preference 
over all the worlds, members of [x] included, and the ©-minimal a;-worlds are deemed 
best among all the a;-worlds, it is reasoned, the set [AT®] should be identified with the 
set of ©-minimal a;- worlds. 

There are two ways of responding to the second issue. On the first count, the princi- 
ple of choosing the best is a vacuous principle devoid of any prescribe content since it 

*. In order to satisfy the principle of category matching, the output should be a pair ©' and 
its arbitrary sphere \K'] = [A'®]. But since [A®] is ©-flat, there is no constructive way of 
generating an expectation ordering ©' in which [K'\ = [A®] is a sphere but not necessarily 
the the central sphere. Hence the principle of category matching is violated by ©. 
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simply means that whatever should be chosen should be chosen. Hence no matter what 
one does, one cannot violate this, as it were, analytic principle. On the second count, 
there is a dual to the principle of choosing the best: the principle of rejecting the worst 
[NF98]. This principle says that in a choice context, reject the worst available alterna- 
tives and retain the rest for further scrutiny. This principle has no less intuitive appeal 
than the principle of choosing the best. Since the set [K] n [x] (respectively, [x]) pos- 
sibly comprises of more than two C-equivalence classes, even after rejecting the worst 
members from [K] n [a;] leaves us with a set [Kf] that is not C-flat, we can impose 
some relevant structure into [Kfj] on grounds no less justifiable than the principle of 
minimality itself. 

Finally, as to the third issue, there are at least two reasons why the principle of 
minimality should be violated both in the context of abduction and revision. Firstly, 
assuming that we employ the principle of rejecting the worst in the context of abduction, 
we need some special, overriding consideration to justify the principle of choosing the 
best (read minimality) in the context of revision. No such overriding considerations are 
available. This is an argument from the classic principle of insufficient reason. Secondly, 
and this is a pragmatic consideration, if we allow the principle of minimality to be 
employed in the context of revision, it is not going to solve the problem of iteration 
so far as acceptance is concerned. Once the agent accepts some belief contravening 
evidence x, the resultant [Ff®] becomes C-flat and we are back to the old problem! 

I take the above discussion to justify the uniform employment of the principle of 
rejecting the worst in a reasoned account of acceptance. 

4 Acceptance Based on Rejection 

I pointed out above that the principle of minimality does not allow the theory of accep- 
tance to extend to an iterative account. I further argued that this principle is no more 
justified than its dual, the principle of rejecting the worst, which, if considered, may 
allow an iterative account of acceptance. In this section I will develop and examine a 
theory of acceptance based on the principle of rejecting the worst. 

4.1 The “Reject Worst Principle” and Acceptance 

The principle of rejecting the worst essentially tells us that in a choice context, reject 
the worst among the available alternatives and retain the rest for further consideration. 
We must add a caveat to this in order to handle the special case when all alternatives 
are deemed to be equally desirable. In such a situation, all the available alternatives are 
worst (and also best). Since the goal is to ultimately choose some member or other from 
the alternatives, I will slightly weaken the principle:® 

® There are choice contexts where an agent may want not to choose any of the available alterna- 
tives. For instance, a selection committee may want to re-advertise a position instead, if none 
of the interested candidates satisfy the minimum prerequisites. There are many ways of look- 
ing at it. An easy way out is to maintain that this set of candidates is not a set of alternatives in 
the first place since they do not satisfy the minimum requirement of being an alternative. There 
are other ways of reconciling this issue as well, but it is beyond the scope of this paper to go to 
the details. 
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- In a choice context, given that not all the available alternatives are equally desir- 
able, reject the alternatives deemed to be worst with respect to the contextually 
defined selection criteria, and retain the rest for future consideration. Otherwise, 
reject none. 

Let us denote the acceptance operation based on this principle of rejecting the worst 
by the symbol o. Figure 4 pictures how different types of evidential data (w, x, y and 
z) are handled by this operation. Note in particular the case of evidence y. In this case, 
the worst elements are rejected not from [y] but from [K] n \y\. If we had rejected only 
the worst elements of [y], the result would not have been a subset of [K], and we would 
have lost part of the information in K, although the evidence is consistent with the 
current knowledge ! 




[Z] 

[Koz] 



[w] = [Kow] 
[X] 

[Kox] 

[K] 

[Koy] 



[y] 



Fig. 4. Acceptance Without Minimality. 



Now I will formally define how, given an appropriate total preorder C on AI and an 
belief set K for C, the non-minimal acceptance operation ©□ (the subscript is hence- 
forth dropped) is constructed: 



Definition 3 (from [T to o) Where O be a total preorder on M and [K] a sphere for C 

if[x\ is O-flat 



'[x] 

{w € [®] I w C w' 
r„oi _ for some w' £ [x]} 

^ ^ ' [A] n [*] 

{w € [K] n [x] I w C w' 

for some w' € [K\ n [*] } otherwise. 



else if [K] n [a:] = 0 
else if[K] n [x\ is Q-flat 



This definition separates four distinct cases and treats them differently. First of all, if 
[x] is flat, irrespective of whether it intersects [K] or not, the result is simply \x\. This is 
because there is not enough structure in [x] to do any more sophisticated operation. Else, 
if [x] is “outside” \K] but is not flat, then the operation o behaves like a non-minimal 
belief revision [NF98]. In the third case, if \x] intersects [K] but the intersection itself 
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is flat, the result simply [K] n \x\. Finally, if the intersection of [K] and [x] is not flat, 
then it behaves like a non-minimal abduction operator. 



4.2 Properties of Non-minimal Acceptance 

I outlined above an account of how the acceptance operator based on the principle of 
rejecting the worst can be constructed. Intuitive though this construction process is, it 
remains to be seen whether this operation has the properties required of an acceptance 
operator. Of the properties this operation satisfies, the following are especially interest- 
ing for reasons to be elaborated afterwards. Note the naming conventions followed: the 
numeric part of the name in general signifies which AGM postulate it is an analogue of 
and the (optional) alphabetic part signifies whether this property concerns the abductive 
behaviour or the revision behaviour of the operator o. For instance, the property (7. lAo) 
corresponds to the AGM postulate (7*) and concerns the abductive behaviour of o. 

flo) is a theory 

(2o) xeK° 

(4o) then Cn{K U {x}) C K° 

(5o) K° = ^x 

(6i?o) lf\- x^y, then K° = K° 

(6Ao) If K \- X ^ y, then = Ky, given that K -■* 

(7.1i?o) UK° % Cn{x A y) then K°^y C Cn{K U {y}) 
given K I ^x 

(7.1Ao) If K° % Cn{K U {x, y}) then K°^y C Cn{K° U {y}) 

(7.2i?o) lfK° = Cn{y) then Kl^y C Cn{K U {y}) 
given K I 'X 

(7.2Ao) lfK° = Cn{K U {y}) then C Cn{K° U {y}) 
given K \f ^x 

(7.3i?o) If A'” n Cn{y) C Cn{x) 

then Kl^y C Cn{Kl U {y}) 

(7.3Ao) If K° n Cn{K U {?/}) C Cn{K U {a;}) 

then K°^y C Cn(K° U {?/}) given h -^x 
(8o) If K° \/ ^y then Cn{Kl U {j/}) C Kl^y 
(9Ro) If K \ — ix, K° I — ly hut x -<y 
then K°^y = Cn{x A y). 

(9Ao) If K VJ {x} ~^y hut K% I — >y 

then Kl;,y C Cn{K U {x, y}). 

For an intuitive understanding of these constraints, it is helpful to view as the set of 
sentences that the evidence a can explain given the background knowledge K. Prop- 
erties (lo-6i?o) are effectively basic postulates of the AGM revision operation, and 
justification for them can be found in [Gar88]. Postulate (6Ao) says that if two pieces 
of evidence contain the same information relative to, and they do not conflict with, the 
current knowledge, then accepting them have the same effect on the current knowledge. 
Note that this is a stronger postulate than (6i?o). Postulates (7.1i?o-7.3Ao) are several 
variations of the AGM postulate (7*). For instance, (7.1i?o) says that, when x conflicts 
with the current knowledge K, if x can explain certain things that cannot be classi- 
cally inferred from x and y together, then everything that x and y may possibly be able 
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to explain can be classically inferred from y together with all that x explains. On the 
other hand, (T.lAo) may be paraphrased as follows: when x does not conflict with the 
current knowledge, if x can explain certain things that cannot be classically inferred 
from K, X and y together, then everything that x and y may possibly be able to explain 
can be classically inferred from y together with all that x explains. All these variations 
of 7* tell us under what condition a piece of evidence y loses its inferential power in 
presence of another piece of evidence x. Postulate (8o) says that x and y jointly fail to 
explain something that follows from y in presence of what is explainable by x only if 
y conflicts with something that is explained by x. Finally, postulates (9i?o) and (9Ao) 
specify the conditions under which x and y cannot explain anything more than what 
can be classically inferred from them, possibly in presence of K. 



4.3 Technical Results 

In this section I will show that the theory of acceptance we have so far developed has 
the desirable features one should expect from it. 1 will omit the proofs due to the space 
limitation. Our first result is the soundness property - that o satisfies conditions (lo- 
9Ao). 

Theorem 1 Let the operation o be constructed from a given total preorder on fA 
and its sphere [K] as specified in Definition 3. The operation o then satisfies the basic 
properties (1 o —QAo). 

The next result (completeness result) shows that given an acceptance operation o that 
satisfies (1 o — 9Ao) and a fixed belief set K, we can construct a binary relation \^ o,k 
with the desired properties. (I will normally drop the subscripts for readability.) In par- 
ticular, I will show that, where C is the relation so constructed: (1) C is a total preorder 
over Ai, (2) the SOS (System of Spheres) corresponding to C has \K] as one of its 
spheres. 

Definition 4 (from o to C) Given an acceptance operation o and a belief set K, 
w Qo,k w' iff either (1) both w G [K] and w' ^ [K] or (2) w G [Kf\ whenever 

w' G [Kf\^for every sentence x such that either (a) K I <x and both w, w' G [x] or 

(b) K 1/ ~^x and both w, w' G [K] n [x]. 



Theorem 2 Let o be an acceptance operation satisfying (lo) — (9Ao) and K a belief 
set. Let be generated from o and K as prescribed by Definition 4. Then C is a total 
preorder on M. such that [K] is one of the spheres ofQ. 

Theorems 1 and 2 jointly provide the representation result. 

Furthermore, the total preorder Cq constructed from a given non minimal revision 
operation o and belief set K is the desired C in the sense the non minimal acceptance 
operation constructed from it, in turn, behaves like the original operation o with respect 
to the belief set K. 
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Theorem 3 Let o be a non minimal belief revision operator satisfying postulates fl o 
—9Ao) and K be an arbitrary belief set. Let C be defined from o and K in accordance 
with Definition 4. Let o' = be defined from C, in turn, via Definition 3. Then for any 

sentence x (and the originally fixed belief set K ) it holds that K° = K° . 

Conversely, one can start with a total preorder C, construct an acceptance operation 
o from it via Definition 3 and then construct a a total preorder C from that o in turn via 
Definition 4, then one gets back the original relation C. 

Theorem 4 Let \—be a total preorder on A4 and [K\ one of its spheres. Let o be defined 
(for K )from C via Definition 3. Let Q'=Qo be defined from o, in turn, via Definition 4. 
Then w 'Qw' iffw C' w' for any two worlds w,w' G M 



5 Discussion 

In this paper, first we argued that although in the literature on belief change, it is taken 
for granted that there can be no meaningful comparison among tenable hypotheses that 
have neither been accepted nor rejected, a case can be made for nontrivial comparison 
among them on the basis of their plausibility. Equipped with a measure that can compare 
among such hypotheses as well as among the beliefs (or disbeliefs, as the case may 
be), we modelled a comprehensive account of acceptance pretty much in the AGM- 
Grove tradition. We then showed that this operation fails to take in to account repeated 
mind change on part of the agent. Accordingly, we developed an alternative theory of 
acceptance based on the principle of rejecting the worst. We motivated it on the ground 
that it can handle the problem of iterated acceptance. 

One of the things pointed out to be crucial in order to handle the problem of iteration 
is satisfaction of the principle of category matching. It is only natural that in order 
to provide an iterated account of acceptance, we identify an expectation ordering that 
succeeds the current expectation ordering after a piece of evidence is accepted. The 
acceptance operation o as described so far fails to do that. Given an expectation ordering 
□ , a belief set K and a piece of evidence x, we know what the new belief set K° would 
be; but we do not know what expectation ordering it is a sphere of. What we precisely 
need is a more general acceptance operation • that accepts as parameters an expectation 
ordering C, a belief set K associated with C and a piece of evidence x and returns a 
new expectation ordering (C, K)% one of whose spheres is AT°. 

In general, there are many ways of satisfying these constraints. However what we 
need is a rational way of satisfying these constraints. In the literature on iterated be- 
lief change, there has been two basic approaches to solve the analogous problem, both 
grounded in Spohn’s seminal work [Spo88]. One, based on what has come to be known 
as conditionalisation has been adopted in many works [Nay94, Wil94]. This approach 
maintains the relative ordering of worlds that are consistent with the evidence as well 
as the worlds that falsify the evidence, but gives more priority to the former class of 
worlds. The other, which has come to be known as adjustment has been adopted by 
[Wil94]. This approach on the other hand maintains the original ordering of all worlds 
that are inconsistent with the new belief set, giving priority only to the worlds that 
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are consistent with the new belief set. In the account that follows, I adopt the former 
strategy. 

Definition 5 Let C be an expectation ordering and K be a theory such that [K] is a 
sphere ofQ. Let x be a sentence. Then (C, itT)* = (C', K') where 

1. K' = K° 

2. w w' for all worlds w, w' iff both 

(a) Either w G [a;] or w' ^ [x], and 

(b) ifw % w' then both w G [x] and w' ^ [x\. 

The first condition, K' = ensures that the revised K matches with the one mandated 
by the acceptance operation o. The first clause of the second condition, namely Either 
w G [x] or w' ^ [x], ensures that in the revised expectation ordering, worlds consistent 
with the evidence x are not accorded less priority than the worlds that falsify such 
evidence. The second clause of the second condition, namely \fw%w' then both w G 
[a;] and w' ^ [a:] ensures that the original priority among worlds is reversed only if it 
conflicts with the principle that worlds consistent with the evidence should be accorded 
more priority than the worlds falsifying the evidence. 

I conclude this section with a quick proof that \Kf\ is indeed a sphere in the expec- 
tation ordering C' thus defined. Suppose that w G [Kf\ and w' C' w but w' ^ \Kf\. 
Since w G \Kf\, surely w G [x]. Since w' C' w, it follows that either w' G [x] or 
w ^ [a:]. Hence it follows that w' G [a;]. However w' ^ [iT°] where from it follows 
that w' % w. It follows from the second clause of the second condition that w ^ [a;] 
contradicting the earlier result that a; G [a;] . ■ 
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Abstract. A new tree-based representation for propositional formulas, 
named A-tree, is introduced. A-trees allow a compact representation for 
negation normal forms as well as for a number of reduction strategies 
in order to consider only those occurrences of literals which are relevant 
for the satisfiability of the input formula. These reduction strategies are 
divided into two subsets (meaning- and satisfiability-preserving transfor- 
mations) and can be used to decrease the size of a negation normal form 
A at (at most) quadratic cost. The reduction strategies are aimed at 
decreasing the number of required branchings and, therefore, these stra- 
tegies allow to limit the size of the search space for the SAT problem. 



1 Introduction 

Efficient representations for formulas in negation normal form (nnfs) are ne- 
cessary in order to describe and implement efficient algorithms on this kind of 
formulas. The ability to reason on specifications written in a language as close as 
possible to natural language is important for information sciences; thus, reaso- 
ning efficiently on nnfs is interesting because these formulas are easier to obtain 
from specifications given in natural language. 

Formulas in conjunctive normal form (cnf or in clause form) are usually 
interpreted as lists of clauses, and formulas in disjunctive normal form (dnf) 
are interpreted as lists of cubes; these interpretations allow efficient descriptions 
and implementations of algorithms to study satisfiability (e.g. linear ordered 
resolution). In this work we use the generalization of these interpretations to 
nnfs given by the A-trees, that is, we use trees of clauses and cubes. Specifically, 
nnfs are represented as trees of clauses and cubes such that each clause-node in 
the tree is an implicant of the formula represented by its scope and, similarly, 
each cube-node is an implicate of the formula represented by its scope. The 
new representation is named A-tree because its nodes are built up from A- 
lists [2]. After defining the notion of A-tree, the operators Norm and A-Tree are 
introduced which, respectively, associate a nnf to each A-tree and vice versa. In 
addition, it can be shown that this correspondence preserves equivalence and. 
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therefore, we can easily extend the concepts of validity and satisfiability to A- 
trees. 

We introduce the concept of restricted Z\-tree (generalizing the well-known 
concept of restricted cnf in which clauses with repeated or contradictory literals 
are not allowed and subsumed clauses are omitted), which involves only restricted 
clauses and cubes in the representation and, in addition, prohibits that a single 
literal is both an implicant and an implicate of the same subformula. 

Later, we introduce meaning-preserving transformations, with at most qua- 
dratic complexity, which eliminate the conclusive or simple nodes and usually 
reduces the size of the input Z\-tree. Roughly speaking, a conclusive node in a A- 
tree is one which can be substituted by a logical constant preserving the meaning 
of the whole tree, and a simple node in a Z\-tree satisfies that the subformula 
it represents is equivalent to a literal; thus, we introduce the so-called restric- 
ted Z\-tree, which generalized the concept of restricted cnf. In addition, several 
satisfiability-preserving transformations are presented with generalize the one 
literal rule and the pure literal rule from the clausal framework. Some of these 
transformations were introduced in [2] , and described using the so-called Z\-sets. 
The fact that Z\-sets are no longer necessary when working with Z\-trees is extre- 
mely interesting when implementing the method, since the simple data structure 
of Z\-tree stores both the information about the structure of the formula and its 
associated Z\-sets. 

Finally, the last section includes some experimental results from an imple- 
mentation of the method described in [2] based on Z\-trees. 

2 Preliminary Concepts and Definitions 

Throughout the rest of the paper, we will work with a classical propositional lan- 
guage, £, over a denumerable set of propositional variables, V, and connectives 
{->, A, V}, the semantics for this language being the standard one. We will write 
A = B to denote that A and B are logically equivalent, and f2 \= A to denote 
that ^ is a logical consequence of 17, that is, any model of 17 is a model of A. 
We will use the usual notions of literal (propositional variable or the negation 
of a propositional variable), clause (disjunction of literals), cube (conjunction of 
literals), and negation normal form (a formula in which the negations are only 
in the literals): 

In this paper, we will always use cubes and clauses ordered by the lexicogra- 
phic order in the set of literals, denoted . 

— A literal £ is an implicant of a formula A \i £ \= A. 

— A literal £ is an implicate of a formula A it A \= £. 

We will use the standard notion of tree and address of a node in a tree [6]. 
An address ry in the syntactic tree Ta of a formula A will also mean, when no 

confusion arises, the subformula of A corresponding to the node of address ry in 

Ta', e will denote the address of the root node. 
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We will also use finite lists written in juxtaposition, with the standard no- 
tation, nil, for the empty list. If A and A' are lists, £ G X denotes that £ is 
an element of A; and A C A' means that all elements of A are elements of A'. 
The conjugate of a literal £ is denoted as I, with the standard meaning, that is, 
p = and ~p = p. If X = £\£<i is a list of literals, then X = £\£i . . .£n 

3 The /1-Trees 

In this section we introduce the concept of Z\-tree as an alternative representation 
of nnfs: 

Definition 1 (.^-tree). A Z\-tree T in C is a labeled tree in the set 

U = {[a]A I A G List(V±) U {_L}} U {[/3]A | A G List(V=^) U {T}} 
inductively defined by the three properties below: 

1. The leaves in a A-tree are elements in TL. 

2. Let Ti, . . . , Tjn be A-trees whose roots are [/3]Ai, • • • , [/3]Am and [a] A G TL, 
then the tree 

[a]X 

T\ ... Tm 

is a (conjunctive) A-tree. 

3. Let Ti, . . . , Tm be A-trees whose roots are [a]Ai, • • • , [a]Am and [/3]A G TL, 
then the tree 

[/?]A 

Ti ... Tm 

is a (disjunctive) A-tree. 

Every Z\-tree T can be interpreted as a propositional formula A in nnf. This 
interpretation also allows to identify the subtrees of T with subformulas of A. The 
idea is just to consider each a-node (resp. /3-node) as a conjunction (resp. dis- 
junction) with the literals in A as immediate successors in addition to the sub- 
formulas represented by its immediate successors, Ti, in the Z\-tree; the nnf so 
obtained from a Z\-tree T will be denoted by Norm(r). In the case of an empty 
clause or an empty cube we have [a]nil = T and [/3]nil = T, that is why the 
definition does not include the cases [a]T and [/3]T. 

We can go the other way round as well, and generate a Z\-tree representative 
for each nnf. But, in order to be able to generalize the reductions to the Z\-trees, 
we want to have more information than this in the lists A, we want to have 
the Z\-lists. In the next section we present a short summary of Z\-lists. These 
were firstly introduced in [1], and have been recently used in the development 
of a large set of reduction strategies for studying the satisfiability of non-clausal 
propositional formulas [2] . 
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3.1 A Short Review of A-Lists 

We associate to each nnf A a pair of lists of literals denoted Aq(A) and Ai{A), 
the so-called associated Z\-lists of A. 

In a nutshell, Aq{A) and Ai{A) are, respectively, lists of implicates and 
implicants of A. 

Definition 2 (A-lists). Given a nnf A, Ao(A) and Ai{A) are elements of 
List(V^)U{T, _L} called A-lists associated with A, recursively defined as follows: 



Ao{e)=£ 
Ao(±) = A 
Ao(T) = nil 

(AL/-) 

^o(VL.a) 



Ao(A,) 



Ai{£) = e 
Ai(_L) = nil 
Zii(T) = T 

(vL/0 



In the definition above there are two versions of the union operator, and 
this can be explained because of the intended interpretation of these sets and 
Theorem 1 below: 



1. Elements in Aq are considered to be conjunctively connected. Namely, if £ 
and £ G Aq(A), then Ao(A) simplifies to _L. This way, we obtain a set of 
implicates which can be thought of as a cube. 

2. Elements in Ai are considered to be disjunctively connected. Namely, if £ 
and £ G Ai(A), then Ai{A) simplifies to T. This way, we obtain a set of 
implicants which can be thought of as a clause. 

The next theorem states that elements of Aq{A) are implicates of A, and that 
elements of Ai(A) are implicants of A. It follows easily by structural induction 
from the definition of A-lists. 

Theorem 1 ([2]). Let A he a nnf and £ be a literal in A then: 

1. If £ G Aq{A), then A\= £ and, equivalently, A = £ !\ A. 

2. If £ G Ai(A), then f j= A and, equivalently, A = £\f A. 

As an easy consequence of the previous theorem we get the following corollary, 
defining a meaning-preserving substitution for a formula A whose result contains 
only one occurrence of any literal in the A-lists of A. 

Corollary 1. Let A a nnf and £ a literal in A. Then: 

1. If£GAo{A), then A = A[£/T,I/A]a£. 

2. If£GAi{A), then A = A[£/A,£/T]\/ £. 



Remark 1. The substitution defined in the corollary above never increases the 
size of A; actually, the size is always decreased but in the following cases: 
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1. If ^ is a conjunctive formula such that i G Aq(A), and there is only one 
occurrence of £. 

2. If zl is a disjunctive formula such that I G Ai(A), and there is only one 
occurrence of £. 



3.2 Back to the ^-Trees 

Given a nnf A, the operator Z\-Tree generates a Z\-tree whose nodes are the 
Z\-lists associated to A. 

Definition 3 (Operator ^-Tree). Let A he a nnf, we generate a A-tree by 
using the operator Z\-Tree, recursively defined as follows: 

1. Let A he a clause, A ±, then Z\-Tree(zl) = [(3]Ai{A). 

2. Let A be a non-literal cube such that A T and A is not a literal, then 
Z\-Tree(A) = [a]Ao{A). 

3. Let A he a disjunctive nnf, and let A\, . . . , An, with n> 1, be the non-literal 
disjuncts of A, then 



Z\-Tree(Zl) = 

j. Let A he a conjunctive nnf, 
conjuncts of A, then 



mi{A) 

Z\-Tree(Ai) ... Z\-Tree(^„) 

and let Ai, . . . , An, with n > 1, he the non-literal 



Z\-Tree(A) 



[a]Ao{A) 

Z\-Tree(Ai) ... Z\-Tree(zl„) 



Example 1. Consider A = {{pA{pV{qAr)))VqVr)A{{pAq)V{pAq))A{{qAp)Vr), 
where every node rj has associated the pair {Aglji), Aifrf)) 



A (<j,nil ) 



V(nil,gr) V (g,nil ) V(nil,r) 

A(p,nil) q r A {pq, nil) A(pg,nil) A {pq, nil) T 

p V(nii,p) p q p q q p 

/\ 

P A(gr,nil) 



q r 
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For the formula A above we have that Zi-Tree(^) is: 

[a]q 

[!3\qr [/3]nil [/3]r 

[a]p [a]pq [a]pq [a]pq 

[0\P 

I 

[a]qr 

Note that for the previous example Norm(Z\-Tree(zl)) is not equal to A, for a new 
literal q is attached as an immediate successor of the root node, making explicit 
that q is an implicate of the formula. Anyway, operators Norm and Z\-Tree are 
inverse, up to equivalence, as stated in the following result. 

Theorem 2. Let A he a nnf. Then A = Norm(Z\-Tree(A)). 

It is remarkable the idea that, in some sense, the structure of Z\-tree allows 
to substitute reasoning with literals by reasoning on clauses and cubes. 

4 Restricted /1-Trees 

In this section, meaning-preserving transformations are introduced which allow 
to reduce the size of a Z\-tree and get a normal form for it. These transformations 
extend to Z\-trees the definitions of Ao-eonclusive, Ai-conclusive and l-simple 
given for nnfs in [2] . 

4.1 Subformulas Which Can Be Substituted by Constants 

The result of Corollary 1 is extended to Z\-trees, in that not only literals, but also 
subformulas can be substituted by the constants T or _L. The operators and 
on Z\-trees reduce a Z\-tree by deleting its redundant nodes, that is, those 
nodes which can be substituted by logical constants in a meaning-preserving 
way. 

Definition 4 (0-conclusive node). Let p be a node of a A-tree T is said to 
be 0-conclusive if it satisfies any of the following conditions: 

— It is labeled with [o;]-L. 

— It is a monary node labeled with [/3]nil. 

— It is labeled with [a] A, it has an immediate successor [/3]A' which is a leaf 
and A' C A. 

— It is labeled with [a] A, its predecessor is labeled with [/3]A' and A n A' yf 0. 

The operator <P± searches for and deletes the 0-conclusive nodes by applying 
the following steps: 
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— If rj is labeled with [a]_L and rj ^ e, then deletes rj. 

— If r] is a monary node labeled with [/3]nil, then <P± deletes rj and collapses 
its ancestors with its (only) succesor. 

— If r] is labeled with [a] A, it has an immediate successor [/3]A' which is a leaf 
and X' C A, then <P± substitutes rj by a[_L]. 

— If r] is labeled with [a]A, its predecessor is labeled with [/3]A' and A n A' ^ 0, 
then deletes rj. 

Intuitively, the previous definition detects those nodes in the Z\-tree which, in 
some sense, can be substituted by _L without affecting the meaning. The effective 
deletion of those nodes is made by an operator, <P±. 

Theorem 3. Let T be a A-tree, the operator <P± has quadratic complexity in the 
worst case, and <P±{T) has no 0-conclusive nodes and, in addition, T = ^x(T). 

The 1-conclusive nodes and the operator are defined by duality, inter- 
changing a and (3, and replacing T by T. 

4.2 Simple Leaves 

In order to get to a restricted Z\-tree it is also necessary to detect which leaves 
are redundant, in the sense that do not represent proper clauses or cubes, but 
literals. 

Definition 5 (Simple node). Let T be a non-leaf A-tree, and let r] be a leaf in 
T. We say that rj is simple if it is labeled with either [a]£ or [P]£, where £ € V^. 

Theorem 4. Let T be a A-tree, then there exists an operator <Pi, with linear 
complexity in the worst case, such that is a A-tree without simple leaves 

and, in addition, T = 

4.3 Updated .^-Trees 

A useful property of the operator Z\-Tree is that, given a nnf A, in Z\-Tree(A) 
the label of each [a] (resp. [/?]) node is the Aq- (resp. Ai-)list associated to the 
subformula that it represents. However, this property need not hold when some 
transformation has already been applied on T. 

Definition 6 (Updated node, updated tree). Let T be a A-tree, and let rj 

be a node ofT that is neither a leaf nor the root. Let [6>]A be the label of the pre- 
decessor of rj, and let [6>]Ai, . . . , [0]A„ be the labels of its immediate successors. 
We say that rj can be updated if it satisfies some of the next conditions: 

1. It is labeled with [0]nil and nr=i{^i> • ■ • ’ ^ 

2. It is labeled with \0]£ for some £ G V* and satisfies both £ 4 X and £ G 

nti{Ai,...,A4. 

We say that a tree T is updated if it has no nodes that can be updated. 
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In order to obtain an updated Z\-tree, we have to drive upwards all those 
literals that can be generated by intersections; this operation is done by the 
operator Update. 

Theorem 5. If T is a A-tree, there exists an operator Update, with quadratic 
complexity in the worst case, such that Update(T) is updated and, in addition, 
Update(T) = T 

4.4 Restricted .^-Trees 

Definition 7 (Restricted tree). Let T he a A-tree. IfT is updated and it has 
neither 0-conclusive nodes nor 1-conclusive nodes nor simple leaves, then it is 
said to be restricted. 

The operators defined in the previous sections allow us to transform every 
Z\-tree in another equivalent and restricted one. 

Definition 8 (Operator Restrict). IfT is a A-tree, Restrict traverses T 
and in every node it tests whether the node is 0-conclusive, or Tconclusive, 
or a simple leaf, or a node that can he updated, and in this case applies the 
corresponding operator in Update}. 

From Theorems 3-5 we immediately obtain the following result. 

Theorem 6. Let T he a A-tree, then Restrict(T) is restricted and, in addition, 
T = Restrict(r). 

Example 2. Given the formula A = (pVq)A(rVs)A((pAq)Vp), whose associated 
Z\-tree is 



[ajp 

[(}]pq [fi]rs [I3]p 

I 

[a\pq 

An application of the operator (node 3 can be reduced) leads to 

[a]p 

[(}]pq [I3]rs [I3]p 

Now, operator Ti is applied to node 3, and we obtain 

[a]p 

[!3\pq [!3]rs 

Finally, operator can be applied again, for the occurrence of p in the root 
allows to reduce that in node 1, giving the restricted Z\-tree 

[a]p 

I 

[/3]rs 

which, using the operator Norm, leads to the formula p A (r V s). 
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5 Equisatisfiability of /\-Trees 

In this section several satisfiability-preserving transformations are introduced 
which allow to reduce the size of a Z\-tree T. These transformations are called 
complete reduction, subreduction (reduction of Z\-subtrees) and a purity rule. 

Recall that the substitution of a logical constant for a literal denoted 
A[i/T , Z/-L], represents the formula obtained from A substituting all occurrences 
of I by T, and all occurrences of I by _L. We extend this notion to Z\-trees using 
the definition below: 

Definition 9 (Substitntions on ^-trees). Let T a A-tree, then T[f'/T,Z/_L] 
denotes the A-tree obtained traversing T and applying the following transforma- 
tions: 

— If £ G X and [/3]A is the label of rj ^ e, then the subtree rooted at rj in T is 
deleted. 

— IfiGX and [a]A is the label ofrj^e, then the subtree rooted at rj in T is 
deleted. 

— If £ G X and [a] A is the label of rj in T, then £ is deleted from X. 

— If£GX and [/3]A is the label of rj in T, then £ is deleted from X. 

— If £ G X and [/3]A is the label of e, then T[^/T,Z/_L] = T. 

— If£ G X and [a]A is the label of e, then T[^/T,£/_L] = _L. 

The following easy-to-prove lemma states that the definition we have just 
given coincides with the usual meaning of substitution in formulas. 

Lemma 1. Let T be a A-tree. Then Norm(r[.^/T,Z/T]) = Horm{T)[£/T ,£/ A]. 

Given a Z\-tree T and a set of literals T, we will denote by T[r /T, T /T] the 
Z\-tree obtained by substituting all the literals of T by T, and their opposite 
by T. 

5.1 Complete Reduction 

The first satisfiability-preserving transformation we are introducing is called 
complete reduction, and can be seen as a generalization of the one literal rule 
in the Davis-Putnam algorithm for satisfiability. We first define what a comple- 
tely reducible Z\-tree is and, then, the corresponding theorem about complete 
reduction is stated. 

Definition 10 (Completely reducible .^-tree). IfT is a A-tree and its root 
is [a] A with X yf nil, we say that T is completely reducible. 

Theorem 7. Let T be a completely reducible A-tree with root [a]A and let T be 
the set {£i \ £i G A}. Then T is satisfiable ijf T[T/T , T/ A] is satisfiable. Fur- 
thermore, if I is a model of T[T /A ,T / A], then any extension I' of I satisfying 
I'{£) = I{£) if £ ^ r, and I'{£) = 1 if £ G T, is a model ofT. 
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5.2 Subreduction 

All the transformations performed by the operator Restrict only use the infor- 
mation of a node and its immediate succesors. The next transformation uses the 
information in a node to simplify all its descendants. 

Theorem 8. Let T he a A-tree and rj a node of T . If [0]A is the label of rj, 
£ € X and there is an ancestor rj' of rj verifying one of the following conditions 

1. [0]A' is the label of rj' , and £ € X' 

2. [0] A' is the label of g' , and £ € X' 

Then the A-tree T' obtained by deleting the subtree rooted atginT is equivalent 
to T . 

It is important to notice that Norm(? 7 ) need not be equivalent to _L or T 
(depending on 0), but the Z\-trees obtained after the substitution are equivalent. 

The next theorem states how a Z\-tree can be reduced when Theorem 8 
cannot be applied. 

Theorem 9. Let T he a A-tree and rj a node of T . If [0]A is the label of rj, 
£ G X and there is an ancestor rj' of rj verifying one of the following conditions 

1. [0]A' is the label of rj' , and £ G A', or 

2. [0]A' is the label of tj' , and £ G X' 

Then the A-tree T' obtained by erasing the literal £ in X is equivalent to T. 

By using Theorems 8 and 9 we can define the operator SubReduce as follows: 

Definition 11 (Operator Subreduce). Let T he a A-tree, then SubReduce(T) 

is the A-tree obtained traversing T in a reverse depth-first order (from leaves 
to the root, and from right to left) and performing the transformations given by 
Theorems 8 and 9. 

The following theorem, a simple consequence of Theorems 8 and 9, states 
that SubReduce implements a meaning-preserving substitution. 

Theorem 10. Let T he a A-tree. Then SubReduce(T) = T . 

Note that for all literal £ in SubReduce(T), no occurrence of £ and £ appear in 
the scope of £. Therefore, only the relevant occurrences of literals are maintained 
after applying subreduction to a formula. 

5.3 Pure Literal 

The concept of pure literal for nnfs in [9] can be immediately extended for A- 
trees, by using Theorem 2. 

If A is a nnf and ^ is a pure literal, then A is satisfiable iff A[£/T] is satisfiable. 
This result can also be extended for Z\-trees. 

A more general concept, that includes the previous one, is the concept of 
Z\-pure literal. 
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Definition 12. Let T a A-tree. We say that £ is a Z\-pure literal in T if, when 
traversing the A-tree in depth-first order, the first occurrence of either £ or I is 
£ in all the branches. 



Theorem 11. Let T a A-tree and £ a A-pure literal in T . Then T is satisfiable 
ijf T[£/T ,1/ 1£\ is satisfiable. 



Example 3. Given the nnf T = (r V s) A (((p V g) A (p V s)) V ((r V ((g V p) A (s V 
g))) A (g V s V r))) A (((p A r) V (p A s)) A g) V s), the associated Z\-tree is 



Of nil 



rs 



[!3\pq 



a nil 



a nil 



1 

[a]pq 

I 

;5lnil 



[I3\pq [(3]ps [I3]qr [0\qrs 

I 

[a]nil [a]pr [a]ps 

[P]pq [P]qs 

The operator SubReduce gives the Z\-tree 



[a]nil 




[a]nil [a]nil [o:]pq 




[a]nil [a]r [a]nil 




Now, the operator deletes the subtree rooted at node 311 and the nodes 
2211 and 21 to obtain the Z\-tree: 



[a]nil 



[l3]rs 



[(i]pqs [/3]s 

I I 

[a]nil [o:]pq 

[fffrs [I3]rs 



Using the operator SubReduce we obtain the Z\-tree on the left and finally, 
applied once again on node 21 gives the Z\-tree on the right: 
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[a]nil 

[(3\rs [(i\pqS [/3]s 

I I 

[a]nil [a]pq 




[a]nil 

1 _ 

[P]rs [/3]pqrs [/3]s 

I 

[a]pq 



Finally, applied once again on node 21 gives the Z\-tree 

Using the operator Norm we obtain the formula {rVs)A{pVqVrVs)A{{pAq)Vs). 



6 Experimental Results 

We have written a straightforward implementation for the Macintosh port of 
the interpreter of Objective CAML (an ML-like functional language) in order 
to obtain a rapid prototype of a theorem prover. Z\-trees have been used to 
implement the reductions just described, together with a naive branching rule 
based on the Davis-Putnam procedure; namely, a formula A is splitted into two 
subformulas A[p/T] and A[p/_L], where p is the first variable occurring in A. 

As our method is specially focused on non-cnf formulas we have run the 
prover, named TAS, on the IFIP benchmarks for hardware verification [3]. The 
results obtained, using a Power Macintosh G3 with 64 Mb of memory and 233 
Mhz, are compared with those obtained in [7], for he also uses there a reduction- 
like strategy (which he calls simplification), in his experiments he used a Sun 
SuperSPARK. In Table 1, we compare our implementation with the results ob- 
tained by Isabelle [8] (a well-known interactive prover, written in Standard ML) 
and Beatrix (a sicstus Prolog implementation in the spirit of lean tableau 
theorem proving). As several strategies were used in the cited work, in fairness 
to Isabelle and Beatrix, we compare our running time with their best absolute 
results no matter the strategy used. 



Table 1. TAS vs Beatrix and Isabelle. 



Problem 


Isabelle 


Beatrix 


TAS 


Problem 


Isabelle 


Beatrix 


TAS 


ex2 


1.3 


0.0 


0.00 


mul 


130.9 


0.2 


0.07 


transp 


0.2 


0.0 


0.00 


rip02 


1.6 


0.0 


0.03 


rise 


9.8 


0.6 


0.05 


rip04 


994.5 


0.5 


0.38 


counter 


68.8 


0.1 


0.13 


rip06 


- 


3.0 


2.75 


ho St inti 


96.5 


0.2 


0.10 


rip08 


- 


18.2 


17.18 



It is important to remark that the results obtained are by far much better 
than those of Isabelle, showing that not only the scaling factor in problems such 
as ripOn can be reduced but also that absolute run time values are comparable to 
those obtained by Beatrix, which shortens the gap between lean theorem proving 
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in Prolog and standard theorem proving in ML-like languages. In Table 2 some 
more results are compared with the run time of Beatrix, where an important 
speed-up when using TAS can be noticed. 



Table 2. Run time (seconds) on other IFIP benchmarks. 



Problem 


Beatrix 


TAS 


Problem 


Beatrix 


TAS 


Problem 


Beatrix 


TAS 


d3 (satisf.) 


0.1 


0.17 


dkl7 


3.0 


0.38 


sqn 


11.2 


0.43 


misg 


0.7 


0.35 


z5xpl 


4.1 


0.38 


addl 


12.2 


1.20 


ztwaalf 1 


0.8 


0.80 


f51m 


5.7 


0.48 


dc2 


12.5 


0.40 


mp2d 


1.1 


1.03 


pitch 


5.7 


2.55 


mul03 


20.1 


1.03 


dk27 


2.2 


0.07 


vg2 


7.0 


2.82 


rd73 


30.4 


1.27 


z4 


2.3 


1.53 


alu 


7.1 


3.98 


root 


33.7 


0.67 


rom2 


2.5 


3.03 


xldn 


7.2 


3.37 


alupla20 


618.1 


31.72 


table 


2.8 


2.72 


z9sym 


9.8 


4.07 









To make the comparison more interesting we also chose to run TAS on the 
Random 3-Sat benchmark, although TAS has not been neither designed nor 
optimised for cnf formulas. Table 3 shows the results for the standard random 
distribution of 3-SAT, where 3_sat(V,C) means that samples had C clauses, 
with 3 literals selected uniformly among V variables and each literal negated 
with probability 0.5. 

We show our results together with the results of two different flavours of Bea- 
trix, the ‘standard’ one (in which the usual /3-rule is used) and the ‘lemmaizing’ 
version (an asymmetric rule for a limited form of cut). 



S, Pi S, P2 

s,p 



Std 



5,/?i S,Pi,P2 

S,p 



Lem 



One can easily see that, although our implementation has been run on a in- 
terpreter (as far as we know no compiler for CAML is still available for Macs) 
the performance of TAS is in between the two flavours of Beatrix. The speedup 
factor of TAS w.r.t. the standard version of Beatrix is about 2 for formulas with 
32 variables and about 3.5 for formulas with 64 variables, whereas the better 
performance of the lemmaizing version of Beatrix averages 1.63 for 32 variables 
and 2.72 for 64 variables. 

These results are neither surprising, for the standard version of Beatrix is 
just a tableau system improved with a particular case of our reductions, nor 
discouraging, for the branching rule we have implemented is just a raw DPLL- 
like procedure. 

It is worth to note that, although the computational pay-off of the reductions 
implemented in TAS results in poor runtimes for the formulas in the first row of 
the table, the negative effect disappears as the size of the formulas is increased. 
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Table 3. TAS vs Beatrix on Random 3-SAT. 



c/v 


Problem 


Beatrix 


Bea-Lem 


TAS 


Problem 


Beatrix 


Bea-Lem 


TAS 


m 


3_sat(32,96) 


0.3 


0.2 


0.80 


3_sat(64,192) 


1.4 


1.0 


7.55 


4 


3_sat(32,128) 


3.9 


1.2 


2.07 


3_sat(64,256) 


334.6 


38.4 


98.31 




3_sat(32,136) 


6.1 


1.8 


3.03 


3_sat(64,272) 


554.3 


56.4 


188.81 


4.5 


3_sat(32,144) 


6.9 


2.1 


3.53 


3_sat(64,288) 


1,050.9 


72.0 


216.64 




3_sat(32,160) 


8.2 


2.4 


3.90 


3_sat(64,320) 


568.6 


60.0 


141.72 




3_sat(32,192) 


7.7 


2.6 


3.71 


3_sat(64,384) 


240.3 


39.4 


90.88 



7 Conclusions 

We have introduced Z\-trees for propositional formulas. This representation al- 
lows a compact representation for well-formed formulas as well as for a number 
of reduction strategies in order to consider only those occurrences of literals 
which are relevant for the satisfiability of the input formula. It is important 
to notice that this structure can be also extended to other non-classical logics 
where the TAS methodology works. Finally, the reduction strategies have been 
implemented and tests are reported which show the relative good performance 
of our implementation of the techniques introduced. 
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Abstract. In this paper we integrate a sorted unification calculus into 
free variable tableau methods for logics with term declarations. The cal- 
culus we define is used to close a tableau at once, unifying a set of 
equations derived from pairs of potentially complementary literals oc- 
curring in its branches. Apart from making the deduction system sound 
and complete, the calculus is terminating and so, it can be used as a 
decision procedure. In this sense we have separated the complexity of 
sorts from the undecidability of first order logic. 



1 Introduction 

In the context of logical systems, sorts are widely accepted as a means of increas- 
ing efficiency, reducing the search space, and allowing more natural representa- 
tions. Two main approaches have been followed in the incorporation of sorts to 
logics. Usually, sorts behave statically when sorts properties -sort hierarchies and 
sort declarations for operations- are fixed in the signature [1,14,13]. 

On the other hand, for the purpose of natural language understanding it 
results interesting to design inference systems which are capable of deducing 
taxonomic information, that is, the reasoning process may actually alter the sorts 
properties such as hierarchies [8]. In this sense, sorts behave dynamically when 
the information about sorts and individuals co-exists within the same formal 
framework [5,6]. The greatest expressivity is achieved when the sort declarations 
of operations are expressed by means of a new formula constructor. Thus the so 
called logics with term declarations [15] arise as logical systems including, in a 
single formalism, a classical many sorted logic together with all the information 
it entails (relations between sorts and sort declarations for function symbols) . 

This paper follows a research line involved in the construction of tableau 
methods for logics with term declarations [7,10,11]. Instead of defining new in- 
ference rules, we separate sorts from first order logic using a sorted unification 
calculus. The calculus is required to unify a set of equations derived from pairs of 
potentially complementary literals occurring in the branches of a tableau. Free 
variables present two difficulties to be considered when designing the sorted cal- 
culus. Firstly, variables are attached to sorts restricting their domain [15,5,6], 
so we can only apply substitutions that are well-sorted. This means that the 
(static) sort of every substituted variable and the (dynamic) sort of the respec- 
tive substituting term must be the same. Second, free variables behave rigidly 
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and so they can only be instanced once [3]. Then we have to consider the sort 
information occurring in the whole tableau even when closing a single branch. 

In this paper, we improve our previous results with a calculus that fulfills the 
following properties: 

1. It is simultaneous, so a tableau can be (globally) closed at once. As we 
will see, the search space can be more efficiently pruned when we consider all 
the branches at the same time. 

2. It is quite simple. It suitably combines a standard unification procedure 
and just four sorted rules (two symmetric non-failure rules and their failure 
versions). Moreover, the applicability conditions of the rules are quite simple. 

3. It is terminating, then we have separated the complexity of sorts away 
from the undecidability of first order logic. Then, the calculus can be used as a 
decision procedure because it is enough to traverse a finite search space. Moreover 
termination allows more elegant soundness and completeness proofs. 

The paper is organized as follows. Section 2 presents the Logic with Term 
Declarations and some results about its ground tableau methods. In Section 3 we 
introduce free variable tableaux and the notion of rigid sorted unification (RSV) 
problem. Section 4 presents a calculus for solving these [/-problems and its 
main properties; it is extended to a global version for solving simultaneous rigid 
sorted unification (S'iJS' [/(-problems in Section 5. Section 6 integrates this last 
calculus into a new free variable tableau system. We finish with a discussion of 
the achieved results. Due to lack of space most of the proofs have been omitted. 
They can be found in [9] 

2 The Logic with Term Declarations LTD 

LTD extends the ordinary first-order predicate logic by introducing a new for- 
mula constructor [ G s (called term declaration) which expresses that the term 
t has sort s. In LTD operations have no static sort, then, a LTD-signature S 
consists of a finite set S of sorts s, and unsorted sets C, T and V of constant, 
function and predicate symbols respectively, the last ones of elements with arity. 
Only variables are attached to a fixed sort; they belong to one of the countable 
sets of the sorted family X = (AT^)sg 5 . 

The sets of 2/-terms T{Ti) and i/-formulas FIX) are defined as in first-order 
logic, but including term declarations. For example, Va;®(a;^ G s') is a formula 
expressing that the sort s is a subsort of s', while Va;^(/(a;®) G s') expresses 
that the range of the function / in the s-domain is a set of s'-elements. A set 
of formulas T, is called a ^-theory, or simply a theory, if it is composed of term 
declarations. Substitutions are finite replacements of variables for terms, written 
in the form [ti/x\^ , . . . 

A ^/-structure D in LTD is a total domain D containing a family of domains 
{D“ I s G S}, and sets of interpretations {c® G D | c G C},{/® : D” ^ D \ 
/" G F}, {P® : D” ^ {[, /} I P" G P}, for symbols of X. Considering that we 
do not have sort declarations in the signature, domains can possibly be empty; 
it is only known that IJ D" C D. 
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A valuation for V is & sorted family p = of finite mappings : 

A® ^ D“ of the form [p®(xf)/a:f , . . . , p®(0/<]; dom{p“) = {x\,...,xl} is 
the domain of p®, and dom{p) = Uses dom(p^) is the domain of p. Note that 
dom{p’^) = 0 if H® = 0. As usual, p[d/a;®] will denote the valuation that assigns 
d to X® and behaves as p elsewhere. 

The semantic value |t]® of a term t in a A-interpretation {T>, p) is defined 
as usual and it exists whenever var{t) C dom{p). The boolean value |(p]® of 
a formula p in {T>,p) exists if free{p) C dom{p) and it is defined as usual for 
first-order formulas, except for: 



- IVa:®pl® 

- Pa:®pl® 

- P e 



f t if M’^[d/x‘] = t, for all d G £1® 

\ / otherwise. 

J t if there exists d G such that = t 

\ f otherwise. 

(tii 

1 / otherwise. 



In the sequel when we write |t]® (resp. |p]®), we assume var{t) C dom{p) 
{free{p) C dom{p)), which trivially holds for ground terms (sentences). 

Next we outline a ground tableau method for LTD. The completeness proof 
of the free variable tableau versions we present will be based on lifting the 
completeness of the ground method. Suppose that A has been extended to a 
signature A, with a countable set of new constants. The rules a and f3 are 
defined as in classical first-order tableaux [4]. For 7 and 5 rules we define: 



Va;®p 3x®p 

7 ) t G s (5) p[c/a;®] 

p[t/a:®] c G s 



In 7, t is a ground term; in d, c is a new constant not occurring in the branch. Note 
how the sort information is managed dynamically in LTD, and term declarations 
are used (t G s) or introduced (c G s) in the branch expansion. 

Definition 1 A branch B of a tableau is closed if an atomic contradiction p and 
^p (p atomic) appears in B. A tableau is closed if all its branches are closed. 



Theorem 2 (Soundness and Completeness) [7] Given a set of B -sentences 
<P, <L> has a closed tableau if and only if is not satisfiable. 



Example 3 Let E be a signature composed of the sorts s, s', the constant a, the 
unary function symbol f and the binary predicate symbol P. Ln order to have 
a more pleasant and direct understanding of the following sentences, we would 
like to refer to sort s as representing human beings, s' as kind people, /(□) as 
giving the father of □, and P{D,0) as expressing that □ gets along with O. 
Suppose that 1: a \s & human being (a G s), 2: which does not get along with 
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its father (^P(o, /(a))), 3: every kind human being gets along with everybody 
(Va;^(a;® G s' ^ ?/®))) and 4- the father of every human being is a 

human being (Vx®/(a;^) G s). Then it is obvious, as the following closed ground 
tableau shows, that ^5; some human beings are not kind G s')). 



5 : G s') 

I 7 to 1, 5 

6 : a ^ s' 

I 7 to 1, 3 

7 : a e s' ^ VyTP(a,y'")) 

d to 7 

8 : -<a G s' 9 : Vj/® (P(a, j/® )) 

closed by 6, 8 I 7 to 1, 4 

10 : /(a) G s 

I 7 to 10, 9 

11 : P{a,f{a)) 
closed by 2, 11 



LTD is not more expressive than first order logic (sorts can be expressed as 
unary predicates [16]), but it allows more pleasant representations and deduc- 
tions. In the example above, the formalization and the tableau can be expressed 
in first order logic, but at the cost of: (1) using more complex formulas (e.g. 
formula 3 would be transformed into yx{S{x) {S'{x) yy{S{y) — > P{x, y)))) 

that produces more branches to be closed) and (2) decreasing the efficiency be- 
cause we loose the sort information in the y-applications (e.g. x in the previous 
formula could be instanced to the term /(/(/(a)))). 

Even if we used static ordered sorts, the formalization of x'' G s' would need 
the sort s ft s', making the signature dependent on the problem. Furthermore 
we can consider a different sort hierarchy in each branch of the tableau. In this 
sense, term declarations improve static ordered sorts as well. 

3 Free Variable Tableaux 

Now we will assume that the extended signature E also contains a countable set 
of new function symbols. The free variable tableau method defines the following 
new rules for quantifications: 



yx^(fi 

(fily^x''] 



6 ') 



3x^(p 



ip[f{x'l\...,xf,^)/x‘] 
/(a;f ,...,<") G s 



Y) 
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In 7 ', is a new variable in the tableau; in 5' , / is a new function symbol 
applied to the free variables occurring in the branch. 

Obviously, free variables of a tableau may be substituted. As variables are 
sorted, the application of a substitution is sound in those contexts which ensure 
that the sort of every substituted variable is preserved. In LTD, theories play 
the role of these syntactic contexts. 

Definition 4 (Well-Sorted Substitution) A substitution\ti/ . ,tn/ 
is well-sorted w.r.t. a theory L, if {U € Si) G C, 1 < i < n. A substitution t 
is well-sorted w.r.t. a tableau T with branches B\, . . . , Bn, if the restriction of 
T to the free variables of Bi, that is T\fnee(Bi)! is well-sorted w.r.t. the theory 
included in Bi, 1 <i <n. 

Well-sorted substitutions can be safely applied to free variable tableaux. De- 
note by 51 the tableau system composed of a, fd, ^',6' and the substitutivity 
rule sub defined by: 

sub) IfT is a free variable tableau and r is an idempotent substitution well-sorted 
w.r.t. T then Tt is a free variable tableau 

The concepts of closed branch and closed tableau are defined as in Definition 
1. Then we can prove the soundness and completeness of 51; these proofs are very 
similar to those presented in [10] (see this paper for more explanations about the 
importance of idempotency in the rule sub and how to overcome empty domains 
-due to empty domains, soundness and completeness of 51 are not stated as 
symmetric results; other approaches about how to overcome the problems of 
empty domains can be found in [2,16]). 

Theorem 5 (Soundness of 51) Given a set of S-sentences <P, if has a 
closed free variable tableau then <P is not satisfiable in structures with non-empty 
domains, for every sort. 



Theorem 6 (Completeness of 51) Given a set of E -sentences <P, if<P is not 
satisfiable then T> has a closed free variable tableau. 

As in classical first-order tableaux [4], improving ground tableaux involves 
to restrict the application of the rule sub and use it only for closing branches. 
This results in the integration of a unification calculus which finds well-sorted 
unifiers for potentially complementary literals occurring in a branch. However, 
in order to perform a complete deduction system, unifiers must be structured in 
a particular form, as the following example shows. 



Example 7 Let T be the closed ground sketch of tableau presented below on the 
left and T' be the free variable tableau built as T on the right. 
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a. £ s 

-.F(o.) 

Va;® (ar« £ s') 

Vw-' P{u'-') 

a E s' 

P{a) 



a E s 

-.F(o.) 

Var® (ar® e s') 

Vw-' P{u'-') 

I 

ar® £ s' 

I 



T' should he closed by solving the unification problem u’^ a corresponding to 
the single branch ofT'; however this problem cannot he solved by any well-sorted 
substitution w.r.t. the theory presented in the branch {a £ s,a;^ £ s'}. Neverthe- 
less there is a sequence of unitary idempotent substitutions a = ][a/x®], 

relating both tableaux, which is gradually well-sorted, in the sense that each uni- 
tary component is well-sorted after the application of the preceding ones in the 
sequence. So a can he applied to T' using the rule sub twice. The sequence a 
emphasizes the idea of an existing order in the application of the rule sub to T' , 
corresponding to the order of ^-applications to T. 

Therefore we will define a unification calculus lifting any closed ground 
tableau to a closed free variable one, by deriving a sequence of well-sorted unitary 
substitutions. Previously we define a concept of triangularity which captures the 
order of 7 -applications to ground tableaux; then we adapt the notion of well- 
sortedness to sequences. 

Definition 8 A sequence of unitary substitutions is tri- 

angular if it satisfies: 

1. var(ti) n = 0, 1 < t < n 

2. Xi ^ Xj , 1 < i < j < n. 



Definition 9 Let a = a\ .. . an, T and T be a triangular sequence of unitary 
substitutions, a theory and a free variable tableau, respectively. We say that a 
is well-sorted w.r.t. L (resp. T), if ai is well-sorted w.r.t. Lu\ . . .Ui-\ (resp. 
Tax . . . ai-i), 1 < i < n. 

Note that well-sorted sequences w.r.t. tableaux can be soundly applied us- 
ing the rule sub, by gradually applying each of its unitary components. So, in 
Example 7, ][a/a;^] is well-sorted w.r.t. T' and can be used to close it. Con- 

sequently we must design a calculus that obtains well-sorted sequences instead 
of a unique idempotent well-sorted substitution. 
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4 Rigid Sorted Unification 

In this section we present how to solve unification problems arising when closing 
a single branch. Specifically, a Rigid Sorted Unification (shortly RSU-)problem 
has the following structure: 

Given a finite theory C and a finite set of equations U , is there a well-sorted 
sequence of unitary substitutions w.r.t. C that unifies U? 

For solving i?5'C/-problems, we define the unification calculus C. The non- 
failure rules of C have the form 



U Cl . . . Cn 
r' Cl ... CnC' 



where r,U' are sets of (oriented) equations and ci...Cn, ci...Cnc' are se- 
quences of unitary substitutions. C is composed of ten rules: six standard rules for 
syntactic unification (tautology, decomposition, orientation, application, clash 
and cycle [16]) plus the following four ones: 

The Sorted Rules of C 



(LW) Left Weakening 

if (t G s) G Cci...Cn and a;® ^ var{t) 

(RW) Right Weakening 

if (t G s) G Lci...Cn and a;® ^ var{t) 

(FWF) Functional Weakening Failure 

if there is no formula t G s in Cc\...c. 

(VWF) Variable Weakening Failure 

if there is no formula t G s in Cc\...c, 
that y® ^ var(t) 





X® ~ t 


r 


Oj_ 








t ~ t' 


, r Cl 






[t/x®] 




' ~x®. 


F 


cri 






y®' : 


i; t, F[t/x^] Cl 






[t/x^] 


a;® 


- f(ti, 


^n)i 


F 


(7l 


• ■ • O'n 






Fail 








that 


X® ^ var{t) 












~x®, F 


CTl 


■ ■ ■ O'n 



Fail 

such that a;® ^ var{t), nor t G s' such 



When solving R6'C/-problems, the application of standard rules has always 
preference. Furthermore we assume that there exists a terminating algorithm A 
for syntactic unification, transforming a set of equations F into Fail or a solved 
set of equations, by the non-deterministic application of the six standard rules. 
In this sense, the algorithm A behaves as a black box and we do not take care of 
the non-determinism its rules entail. Incorporating auxiliary calculi for solving 
some well-stated problems has been used in many other areas [3,12]. 

Definition 10 Let F be a set of equations and c = c\ . . .Cn a sequence of 
unitary substitutions. One C-standard step is the application of the algorithm A 
to the pair {F, c) until Fail or a solved set of equations F' is reached. One C-sorted 
step is the application of a sorted rule to the pair {F, c) using a theory. One C-step 




200 



Pedro J. Martin and Antonio Gavilanes 



is one C-standard or C-sorted step. We write (F, a\ . . . cr„) \~c {F', cti . . . 

(n' € {n, n+1}) (resp. (F, (Ti . . . (j„) \~c Fail) to express one non-failure (resp. 
failure) C-step. 

We say that the calculus C unifies a set of equations F w.r.t. a theory L by 
the sequence of unitary substitutions ai . . . cr„, or cti . . . cr„ is a C-unifier for F 
w.r.t. L, if there exists a chain of C-steps, alternating C-standard and C-sorted 
steps, starting with {F, 0) and finishing with (0, a\ . . . an). 

Note that C-standard steps do not append elements to the sequence of unitary 
substitutions, and they can possibly be empty if the set of equations is still in 
solved form after one C-sorted step. Note also that C-sorted steps are always 
applied to sets of equations in solved form. 

The computation of a solution to a i^b’U-problem can be viewed as the search 
for C-unifiers in a C-derivation tree: nodes are either pairs {F, a) or failure 
leaves Fail, and branches alternate C-standard and C-sorted steps. Branching 
in a node only occurs due to (explicit) non-determinism in C-sorted steps; the 
non-determinism derived from syntactic unification is implicit in the algorithm 
A. Leaves are either successful pairs (0, a) or failure leaves Fail. As we will see, 
a failure node after one C-standard step allows to cut the branch expansion of 
that node, while after one C-sorted step, allows to cut the branch expansion of 
its parent. 

Example 11 Suppose C = {a G s,y^' G s,z‘‘" G s,b G s'} and F = {/(x®) ~ 
/(6)|. The C-derivation tree for this RSU-problem is: 



{fix") ~ f(b), 0) 



C-standard step 



~ 6 , 0 ) 




(a C::! b, [a/fc^]) 



~ b, [z" [x"]) {y" 



b, [y"‘ fx"]) 



C-standard step | 
Fail 



C-standard step | | C-standard step 

{z"" Zib, [z"“ [x"]) {y"‘ Zib, [y"‘ fx"]) 

FWF I I LW 

Fail (6 ~ 6, [y"' lx"][b/y"']) 



C-standard step 



(0, [y"‘ lx"][bly"‘]) 



The first branch finishes in a failure node after one C-standard step, and the 
second one, after one C-sorted step. The third branch obtains the unique C -unifier 



[//a:®] [6//]. 
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4.1 Properties of the Calculus C 

First we show that the unification calculus C is terminating for every RSU- 
problem. 

Theorem 12 (Termination) The C-derivation tree of every RSU-problem is 
finite. 

The calculus C is sound in the sense that given a set of equations T and a 
theory C, every C-unifier is a solution to the corresponding _R5'C/-problem. 

Theorem 13 (Soundness) Let T,C and a he a set of equations, a theory and 
a sequence of unitary substitutions, respectively. IfC unifies T w.r.t. C by a then: 

(i) a is well-sorted w.r.t. L 

(ii) a unifies T. 

The completeness of C should read as follows: if there is a well-sorted sequence 
of unitary substitutions a w.r.t. C unifying T then C unifies T w.r.t. T by a 
sequence r which is more general than a* . But we are only interested in lifting a 
particular class of sequences of unitary substitutions, those sequences cr derived 
from a closed ground tableau T in the following way. Let T' be a free variable 
tableau built as T, then cr is obtained by appending unitary substitutions to the 
sequence which correspond to the y-applications to T; that is, if Va;®(p and t G s 
is used in T then we add to the beginning of the current a, where t' G s 

is the term declaration associated to t G s occurring in T'. In Example 7, we 
would obtain ][a/a;®]. These sequences are ground and can be captured 

by the concept of hyperwell-sortedness. Only hyperwell-sorted sequences will be 
considered in the completeness of C. 

Definition 14 A triangular sequence of unitary substitutions [ti/xfi^] . . . [t„/ 
is hyperwell-sorted w.r.t. a theory L, if (fi G Si) G C, 1 < i < n. 

In a hyperwell-sorted sequence, the order of the substitutions is not relevant 
because the declaration of the replaced term explicitly appears in the theory. It is 
immediate that every hyperwell-sorted sequence is also well-sorted; the inverse is 
not true, for example [a / x’^][a / ] is well-sorted but not hyperwell-sorted w.r.t. 
the theory {a G s,x’^ G s'}. 

For proving completeness, we examine the standard and the sorted case. For 
the former, we suppose that the algorithm A for syntactic unification is complete, 
so it fails whenever the given set of equations is not syntactically unifiable, and 
it succeeds giving a solved set of equations, otherwise. For the latter, we prove 
the following results. First the next technical lemma states that extracting and 
moving a unitary component through a sequence, from its place to the beginning, 
preserves hyperwell-sortedness and does not change the substitution. 

* Sequences of unitary substitutions are compared through the respective substitutions 
resulting from composing their unitary components. 
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Lemma 15 Let cti . . . cr„ be a sequence such that Gi = 1 <i <n. For a 

fixed m € {1, ■ ■ . ,n} we define tr' = [ti[tm/xf^]/xfi], 1 < i < m — 1. If a\ .. .an 
is hyperwell-sorted w.r.t. a theory C then: 

1. a'l . . . a'^_iam+i ■ • ■ is hyperwell-sorted w.r.t. Cam 

2. arnGi . . . am — l^m-\-l • . • Gn = fJi . . . Gn. 

The next two lemmas prove completeness of the sorted case. If a set of equa- 
tions is unifiable by a hyperwell-sorted sequence then one non-failure C-sorted 
step can be taken because we can extract a unitary component from the sequence, 
as in Lemma 15. This step is always feasible since in a hyperwell-sorted sequence 
the declaration of every replaced term explicitly appears in the theory, wherever 
it occurs in the sequence. Conversely, if one failure C-sorted step proceeds then 
the set of equations is not unifiable by any hyperwell-sorted sequence. 

Lemma 16 (Sorted Completeness) Let F and C he a solved non-empty set 
of equations and a theory, respectively. Let t = t\ . . .Tn he a hyperwell-sorted 
sequence w.r.t. C that unifies F. Then there exists a set of equations F' and a 
unitary substitution a such that {F,ll)) \~c {F',a). Moreover there exists another 
hyperwell- sorted sequence 9i .. .9k w.r.t. La unifying F' . 



Lemma 17 (Sorted Failure) Let F and C he a solved set of equations and a 
theory, respectively. If (T, 0) \~c Fail after one C-sorted step then there is not a 
well-sorted, therefore neither hyperwell-sorted, sequence w.r.t. C unifying F. 



Theorem 18 (Completeness) . Let F and C be a set of equations and a theory, 
respectively. Let gi . . . Gn he a hyperwell-sorted sequence w.r.t. C unifying F. 
Then there exists a C -unifier for F w.r.t. C. 

Then we can solve a given i?5'C/-problem by examining its C-derivation tree. 

Corollary 19 The RSU-problem is decidable. 

Proof. Given a iJb' C-problem and its associated C-derivation tree: 

(i) answer yes whenever there is a successful leaf. This answer is correct by 
Theorem 13, 

(ii) answer no whenever every branch ends in a failure node. In this case there 
is no hyperwell-sorted sequence w.r.t. the theory, by Theorem 18. Although the 
notions of hyperwell-sortedness and well-sortedness are not equal, this answer 
is correct because their mutual existence is equivalent, as the following result 
proves. ■ 



Theorem 20 There exists a hyperwell-sorted sequence w.r.t. C unifying F if 
and only if there exists a well-sorted sequence w.r.t. C unifying F. 
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5 Simultaneous Rigid Sorted Unification 



In the sequel, T is a free variable tableau with branches i?i, . . . , Bm- 

Rigid sorted unification can be introduced in a tableau system in two differ- 
ent ways. In a first approach, we can use the calculus C to close only a single 
branch each time; this approach, followed in [10] but using a non-terminating 
variant of the calculus C, presents a clear disadvantage. The point is that well- 
sortedness w.r.t a branch is not equivalent to well-sortedness w.r.t. the whole 
tableau, because free variables can occur repeated in different branches. In fact, 
not every local well-sorted unifier (w.r.t. the theory included in the branch to 
be closed) is well-sorted w.r.t. T, so an extra test is needed to check that the 
obtained local C-unifier is applicable to (well-sorted w.r.t.) T. Observe that this 
test can only fail or succeed after the local C-unifier has been totally built. 

In a second approach, we can try to close the whole tableau in a single 
step, looking for a simultaneous well-sorted unifier. In this setting, we try to 
unify a set of equations B composed of one pair of potentially complementary 
literals from each branch of T. A simultaneous calculus avoids the disadvantage 
of the local calculus because it considers all the branches at once; so it implicitly 
incorporates the previous extra test every time the sequence is extended. In this 
sense, a simultaneous calculus prunes the search space more than a local calculus, 
because it does not extend wrong sequences that are not going to become well- 
sorted w.r.t. the whole tableau. 

Following this approach, the Simultaneous Rigid Sorted Unification (shortly 
SRSU)-problem arises: 

Given a free variable tableau T and a finite set of equations U, is there a well- 
sorted sequence w.r.t. T that unifies U? 



For solving SRSU-pr oblems, we define the calculus T>. It is a natural extension 
of C, in the sense that it takes care of all the branches of T when a new unitary 
substitution is added to the sequence. The calculus T> is composed of the six 
standard rules for syntactic unification and the natural extension of the previous 
C-sorted rules. For example: 



(LW) Left Weakening 



~t' , r (Ti . . . Gn 

t~t',r (Ti . . .an[t/x‘^] 



if ^ var{t) and for each Bj (x^ G free{BjGi...an) (t G s) G BjGi...an) 



V is used similarly to C, that is alternating standard and sorted steps until the 
set of equations to be unified is empty. Then the notions of I?-step (standard or 
sorted), I?-unifier and I?-derivation tree can be defined as we did in the previous 
section, but using a free variable tableau instead of a single theory. Moreover we 
can prove that the calculus T> satisfies the same properties. 



Theorem 21 (Termination) The V-derivation tree of every SRSU-problem is 
finite. 
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The calculus V only builds well-sorted sequences w.r.t. a free variable tableau 
T that unify the initial set of equations F. Hence, we can answer yes to the 
corresponding SRSU-prohlein, whenever a I?-unifier exists. 

Theorem 22 (Soundness) Let F,T and a be a set of equations, a free variable 
tableau and a sequence of unitary substitutions, respectively. IfV unifies F w.r.t. 
T by a then: 

(i) a is well-sorted w.r.t. T 

(ii) a unifies F. 

As in the previous section, in a tableau system we are not interested in 
any sequence that can be inferred from a closed ground tableau. To this end 
hyperwell-sortedness is extended to tableaux and the completeness theorem is 
stated. 

Definition 23 A triangular sequence of substitutions \ti/ x\^] . . .[tn/ xf;^] is 
hyperwell- sorted w.r.t. a free variable tableau T, if xl' G free{B) (fi G 
Si) G B, 1 < i < n, for every branch B. 



Theorem 24 (Completeness) Let F and T be a set of equations and a free 
variable tableau, respectively. Let cti . . . cr„ be a hyperwell- sorted sequence w.r.t. 
T unifying F. Then there exists a T> -unifier for F w.r.t. T. 

It is important to note that we can not solve a given SRSU-prohlem by 
examining the associated finite I?-derivation tree (cfr. Corollary 19) because a 
similar result to Theorem 20 does not always hold for the simultaneous case, as 
the next example shows. 

Example 25 Let T be the sketch of a free variable tableau below. The sequence 
[a/z® ][a/a;®] is well-sorted w.r.t. T and unifies {a ~ a;®}, so [a/z® ][a/a;®] is 
a solution to the related SRSU-problem and T could be closed. However it does 
not correspond to a closed ground tableau; in fact, there is not a hyperwell-sorted 
sequence, nor a V-unifier neither, because, in the first branch, x® had to be bound 
to the constant a while, in the second one, to z® . 



^P(a) 

(a G s A P(x^)) V (Vz^ (z^ E s) A a E s' A P(x^)) ) 




a E s 


a E s' 


p(xA 


p(xA 




Vz'-'z'-' 



E s 
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This example has two consequences. On one hand, the calculus V does not 
completely solve the ^i^^U-problem, although the completeness of the tableau 
system will not be affected. On the other hand, the decidability of the SRSU- 
problem remains open. 



6 Free Variable Tableaux with Simultaneous Rigid Sorted 
Unification 

Now we use the calculus T> for defining the tableau system 52 which is composed 
of the rules a,/3, 7',<5' and the new closure rule: 

(SRSU-Closure Rule) A free variable tableau T with branches is 

closed if there exist a set of equations T = {Li ~ L[, . . . , Lm — L'^}, where 
Li ~ L' corresponds to a pair of potentially complementary literals occurring in 
Bi, and a V -unifier w.r.t. T unifying B 

We use the system 52 for building closed tableaux as follows: 

1. Expand non-deterministically the tableau, using the rules a, ,6' . 

2. Define a set of equations B by selecting one pair of potentially comple- 
mentary literals from every branch of the current tableau. Build the finite 15- 
derivation tree for B w.r.t. the current tableau. If a 25-unifier exists then the 
tableau is closed, using the SRSU-closure rule; otherwise, try with another set 
of equations, if there exists another choice, or go back to 1. 

Observe that the unique step taking sorts into account (step 2) always fin- 
ishes -it can be seen as a decision procedure. Therefore we have separated the 
complexity of sorts away from the undecidability of first order logic. 

Theorem 26 (Soundness of 52) For every set of E -sentences <P, if <P has a 
closed free variable tableau then <P is not satisfiable in structures with non-empty 
domains, for every sort. 



Theorem 27 (Completeness of 52) For every set of E -sentences <P, if <P is 
not satisfiable then has a closed free variable tableau. 



Example 28 We use the system S2 to solve the problem of Example 3. First 
we apply rules 7 and (3 to build the free variable tableau T: 




206 



Pedro J. Martin and Antonio Gavilanes 



5 : (x^ G s') 

I 7 to 5 

6 : x^ ^ s' 

I 7 to 3 

7 : xJ £ s' ^ yy‘(P{z%y^)) 

/9 to 7 

8 : ^ 2 “ G s' 9 :\/y‘{P{z‘ ,y‘)) 

I 7 to 4 

10 : J(y‘) G S 

I 7 to 9 

11 : P(z‘,u‘) 



Second we use the calculus V to unify the set of equations F = { 2 ® ~ a;®, z® ~ 
a, u® ~ /(a)} w.r.t. T. Observe that V has to succeed because F is unified by 
the hyperwell- sorted sequence [/(y®)/M®][a/y®][a/z®][a/a;®] (this is the sequence 
that relates T to the ground tableau of Example 3). Next we show a successful 
V-derivation for F w.r.t. T: 



LW 


{z® ~ ~ a,u‘^ ~ 


[a./z-] 


{a , a a, /(a)} 


LW 


{a:® ~ a, u® ~ f{a)} 


[a[zP][(i[x‘'] 


{a C::! a,u^ C::! 


LW 


{u® ~ /(a)} 


[alz%alx^][f(y^)lu^] 


{/(r“) ^ f{a)} 


LW 


{y® - a,} 


[a/0®][a/a7®][/(j/®)/-u.®][a/j/®. 


{a 2::; a} 



Let us compare the simultaneous calculus V w.r.t. a local approach (cfr. be- 
ginning of Section 5) consisting of a) the local calculus C applied to each branch 
independently and b) a test for checking whether a C-unifier is a well-sorted 
sequence w.r.t. the whole tableau T . Then we must solve the following two prob- 
lems: 

1) {z® ~ a;®} w.r.t. the theory {o € s,a;® G s'} 

2) {z® ~ a,M® ~ /(a)} w.r.t. the theory {o G s,a;® G s' ,f{y’^) G s| 

In the second problem, we can apply the C-rule LW, using the declaration f(jj") G 
s, to obtain the unitary substitution a = [/(y®)/z®]. However, any sequence ex- 
tending a will not be well-sorted w.r.t. T (the test will fail, but only once the 
C-unifier has been totally built!) and so the C -derivation subtree following this 
step is useless. In this sense the calculus V is more efficient because it prevents 
the extension of wrong sequences that are not going to become well-sorted w.r.t. 
the whole tableau. 
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7 Conclusions and Related Work 

We have presented the logic with term declarations LTD. This is an order-sorted 
logic which extends the classical first-order logic by introducing a new formula 
constructor t € s, allowing the dynamic declaration of the term t as an element 
of sort s. Logics with terms declarations already appeared in [5,15,16]- There 
variables can be restricted to non unitary sorts; for example, denotes an 

individual of the intersection sort s H sL In LTD, this sorted variable can be 
expressed including the term declaration x® € s' where needed. 

Apart from our previous papers, tableau methods only concern [16]. [5] and 
[15] consider resolution based methods, the former in a more general frame- 
work. In these two papers, sorted variables behave as universal in the involved 
unification processes, in contrast to the rigid approach used in tableaux. 

When dealing with free-variable tableau versions for LTD, the first question 
to be solved is how to define sound substitutions of variables in tableaux. This 
concept is the key to perform a proper integration of any sorted unification 
calculus into a tableau system. In [10] we proved that some possible attempts 
to define a substitutivity rule (cfr. [16]) fall into error. In this sense, the (de- 
cidability) results about rigid sorted unification presented in [16] seem to be 
useless for tableaux because its calculus is sound and complete w.r.t. an unsafe 
well-sortedness definition; that is, the application of its involved unifiers in its 
calculus produces unsound tableau systems. For this reason, decidability results 
for a sorted unification method useful for tableaux remained open till now. 

Regarding our previous paper [10], there are two main differences. First, [10] 
presented a local unification calculus that required an extra test to check well- 
sortedness w.r.t. the whole tableau; second such calculus was not terminating. 
Now we have defined the simultaneous unification calculus D which implicitly 
incorporates the extra test every time a sequence is extended. In this sense, we 
have also shown that the calculus D prunes more efficiently the search space. 
Moreover D is terminating, so it can be successfully integrated in a tableau 
system unlike the calculus presented in [10]. Observe that non-terminating uni- 
fication calculi are useless within a tableau system because they can never end 
when trying a non-unifiable problem. 

The calculus D also improves [10] in other minor points. It has less rules 
with simpler applicability conditions. Due to termination, the technique used 
for proving the completeness of D is different and it strongly simplifies the te- 
dious proof for the calculus presented in [10]. Now we easily state completeness 
proving that the existence of hyperwell-sorted solutions can be preserved in the 
^-unification process. 

At present, we are working on a prototype of the tableau system 52. As in 
this paper, we proceed by steps: first implementing the previous sorted calculus 
C, then the calculus D, and finally, incorporating D to free variable tableaux. 
As future work, it would be useful to design efficient strategies to transform the 
non-deterministic calculus D into a real decision procedure. 
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Abstract. Code trees [8] is an indexing technique used for implementing 
several indexed operations on terms in the theorem prover Vampire [5]. 
Code trees offer greater flexibility than discrimination trees. In this paper 
we review a new, considerably faster, version of code trees based on a 
different representation of the query term. We also introduce a partially 
adaptive version of code trees. 

Keywords: automated theorem proving, subsumption, matching, term 
indexing, code trees 



1 Introduction 

In [8] code trees, a new indexing technique for forward subsumption, was pre- 
sented. In order to implement efficiently forward subsumption on a large set 
of clauses a general subsumption algorithm is specialised at run time for each 
particular clause in the set. The specialised version of the algorithm is repre- 
sented as a sequence of instructions of some abstract machine. Such codes are 
integrated into an indexing structure — a code tree, which allows one to per- 
form subsumption check by the whole set of clauses at once. Although code 
trees can be considered as a differently presented version of discrimination trees, 
the compilation-based approach gives some serious advantages. Code sequences 
for indexed terms are rather flexible objects as they allow various equivalence- 
preserving transformations to be performed on the index. This flexibility enables 
invention and formulation of new optimisations. Exploiting the notion of abstract 
machine makes description of the indexing technique more machine-oriented and 
its efficient implementation feasible. 

Although experiments with the original version of code trees have shown high 
effectiveness of the compilation-based approach, a case study revealed that the 
original formulation of this technique leaves space for significant improvements. 
In this paper we discuss several improvements implemented in version 0.0 of 
Vampire [5] that has won CASC-16 [7] in the MIX division and CASC-I7 in the 
EOF division. 

The main improvement was achieved by changing the representation of query 
clauses. The original version [8] deals with query terms represented as tree-like 
structures. It has been discovered that the flatterm [I] representation of query 
clauses eliminates the need for some operations in code trees and also makes the 
expensive operation of term comparison faster. We will describe the new version 
of code trees in Section 3. 
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Apart from the representation of queries, another shortcoming in the origi- 
nal version of code trees is worth special attention. There are two factors that 
can increase the efficiency of indexing techniques: early detection of failure and 
better sharing of structure (or in our case sharing of code). In the case of code 
trees early detection of failure can be achieved by applying term comparison 
instructions as early as possible. At the same time this can deteriorate sharing 
to a very high extent, so that the size of a code tree grows as much as 10 times 
on some benchmarks. In Section 4 we describe a partially adaptive version of 
code trees in which both early detection of failure and better code sharing is 
achieved by moving term comparison instructions up and down the tree during 
the compilation of indexed terms. Moreover, we can change the comparison in- 
structions to achive better sharing. We call the resulting version of code trees 
partially adaptive because the tree can adapt to insertion of new instructions 
by changing itself. The ability to partially adapt code trees with small overhead 
shows their advantage over the more standard data structures used for forward 
subsumption and similar clause retrieval operations, for example discrimination 
trees [3]. Finally, in Section 5 we describe experiments with partially adaptive 
code trees. 

2 Preliminaries 

We assume acquaintance with the basic notions of terms, substitutions and 
clauses. A clause C\ subsumes a clause C 2 if there exists a substitution 6 such 
that Cl 0 is a subset of C 2 . In [8] indexing for multiliteral clauses was done by 
composition of indexes for their literals. Since our current approach to dealing 
with multiliteral clauses does not differ from the one of [8], it is sufficient to 
consider only the unit clause case in order to illustrate our main optimizations. 
In the case of unit clauses, subsumption can be reformulated as the matching 
problem on terms. We say that a term t 2 matches a term t\ if there exists a 
substitution 6 such that t\6 = t 2 - In this case we will also say that t\ subsumes 
t2- 

We will follow the general framework of term indexing presented in [4]. In 
general, the term indexing problem can be formulated as follows. Given a set 
of terms I, called the set of indexed terms and a single term t, called the query 
term, we have to retrieve quickly each term s G I such that a retrieval condition 
R holds between s and t, i.e. we have R{s,t). For the purpose of this paper 
the retrieval condition R is forward subsumption: R{s,t) holds if s subsumes t. 
The term indexing problem consists of finding a datastructure, called the index 
which allows one to perform efficiently the following operations: term retrieval, 
i.e. finding all (or some) s € / that are in relation R with the query term t, and 
index maintenance: changing the index when terms are inserted into or deleted 
from, the set of indexed term. 

A code tree is a datastructure for term indexing. The main idea of code 
trees is as follows. Let A be a procedure for performing forward subsumption, so 
F{s,t) returns true is s subsumes t. For each indexed term s S / we specialize 




Partially Adaptive Code Trees 211 



F by fixing its first argument to s. This specialized procedure is denoted by Fg, 
thus we have Fs{t) = F{s,t) for all terms s and t. The procedure Fg for each 
indexed term s € / is represented as a sequence of instructions of an abstract 
subsumption machine. There is a small number of instructions, some of them 
have parameters. Then the procedures {fs | s G /} are combined into a larger 
set of instructions T/, called the code tree for I. The set of instructions Fj is 
better viewed as a tree rather than a sequence, hence the name code tree. The 
set of instructions Fj is a procedure that can be executed on any query term t 
such that Fi{t) ^ (3s G I)Fg{t). 

3 Code Trees for the Flatterm-Based Representation of 
Query Terms 

In this section we describe a version of code trees obtained by adapting the 
original one of [8] to the new representation of queries. Following [8], we start 
from considering compilation of terms for the case of forward subsumption by one 
clause. To represent our algorithms formally, we will need quite a few definitions. 

3.1 Positions in Term 

If t is a term, top{t) denotes the top symbol of t defined as follows: 

, f t, if t is a variable or constant; 

= I/, iff = 

We call a position any finite sequences of natural numbers, including the empty 
sequence, denoted by A. The notion of position in a term t and the subterm of 
t at a position p, denoted t/p, are given by the following definition. 

1. the empty position A is a position in t and tfX = t. 

2. if tjp = f(fi, . . . , tn), n > 0, then p.l, . . . ,p.n are positions in t and t/{p.i) = 
ti for alH G {1, . . . , n}. 

Posff) will denote the set of all positions in t. For technical purposes we we 
extend Pos{t) by a special object £ called the end position in t. The set Pos{t) U 
{e} will be denoted by Pos~^{t). When it is necessary to tell the end position 
from other positions, we call the positions from Pos{t) proper positions. Size 
of a term t, denoted |t|, is defined as the number of proper positions in t. We 
denote by < the lexicografic ordering on positions extended in the following 
way: p < e for any proper position p. To perform traversal of a term t we will 
need two operations on proper term positions: nextt and after which can be 
informally explained as follows. Represent the term t as & tree and imagine a 
term traversal in the left-to-right, depth-first direction. Suppose tjp = s. Then 
t/nextt{p) is the subterm of t visited immediately after s, and t/after^{p) is the 
subterm visited immediately after traversal of all subterms of s. Formally, let 
X = Pi < . . . < Pn < Pn+i = £ be all positions in t. Then nextt{pi) = Pi+i for 
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all i < n. The definition of after ^ is as follows: after ^{X) = s and for 1 < f < n 
after f{pi) = pj, and j is the smallest number such that j > i and for alii < k < j 
the position pi is a prefix of pk- 

As it was mentioned, our new code trees are interpreted on queries repre- 
sented as flatterms. In Vampire we use an array-based version of fiatterms. A 
term t is represented by an array of the size |t|. Let pi < . . . < be all positions 
in t. Then the z-th element of the array is a pair (s, j), where s = topft/pf) and 
Pj = after ^{pi). 

In can be seen that computation of our major operations on positions, nextq 
and after can be done very efficiently on such a representation, nextq is com- 
puted by a simple incrementation of the corresponding subscript, so nextq{pi) = 
Pi+i, and the subscript of after q{pi) is given in the zth element explicitly. An- 
other serious advantage of this representation in comparison with tree-like terms 
is that equality of two subterms q/pi and q/pj can be checked efficiently, without 
using stack operations. 

For technical purposes we introduce a new set of variables *i, * 2 , ■ ■ ., called 
the technical variables. A term containing no technical variables will be called 
an ordinary term. Let A = po < Pi < ■ • ■ < Pn be all proper positions in t. Then 
for z S {0, . . . , n}, pos^ft) will denote pi. 

Let pkj < ... < pk^ be all such proper positions in t that top{t/pkf) is a 
variable. The i-th variable position in t, denoted by vp^{t), is defined as vp^{t) = 
Pki. For i > m vp^{f) is undefined. The technical skeleton of a term t, denoted 
by tsk(t), is the term obtained from t be replacing the subterm of t at the zth 
variable position by the technical variable *i, for all z. For example, the technical 
skeleton of f{xi,a, g{xi,X 2 )) is /(*i, a, g{* 2 , * 3 ))- 

The variable equivalence relation for a term t, denoted St, is the equiva- 
lence relation on {1, . . . ,m} such that: (i,j) € St if and only if top{t/ vp^^it)) = 
topft / vp j{t)) . For example, the variable equivalence relation for f{x\,a, g{x\,X 2 )) 
consists of two equivalence classes: {1,2} and {3}. The pair {tsk{t),St) will be 
called the technical abstraction of t. Note the two terms have the same tech- 
nical abstraction if and only if they are variants of each other. If is a bi- 
nary relation, B~ denotes the transitive, reflexive and symmetric closure of 

If £ is an equivalence relation and B is such a binary relation that B~ = 
S, then B is called a frame of S. A frame is called minimal if no proper 
subset of it is a frame. Throughout the rest of the paper we consider only 
equivalence relations over finite sets of the form {!,... ,m}. A finite sequence 
(zzi, ui), . . . , (zzfe, Vk) of pairs of integers is called a computation sequence for S if 
the relation |(zzi,z;i), . . . , {uk,Vk)} is a minimal frame of S and ut < vt for all 
z G {1, . . . , k}. Such a computation sequence is called canonical if each Ui is the 
minimal element of its equivalence class in S and for i < j Vi < Vj. Note that 
the canonical computation sequence is uniquely defined. 
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3.2 Compilation for Forward Subsumption by One Clause 

We are going to solve the following problem: given a term t and a query term q 
we have to check if t subsumes q. Figure 1 shows a deterministic algorithm that 
does the job. 



procedure Subsume{t,q) 

begin 

/* First phase: term traversal */ 

let subst be an array for storing positions in q\ 

post ■= >^\ 

POSg := A; 

while poSt 7^ e 
if tsk{t)/poSt = *i 
then 
subst[i] := 

poSg := after g(poSg)-, 
post ■= after t[post)\ 
else /* t/poSt is not a variable */ 
if top{t/poSt) = top{q/pos^) 

then 

poSq := nextq[pos^)\ 

poSt '■= nextt(poSt)’, 
else return failure; 

fi; 

fl; 

end while : 

/* Second phase: comparison of terms */ 

let {ui, vi), , {un, Vn) be the canonical computation sequence for £t. 
i := 1; 

while i < n 

if q/subst[ui] 7^ q/subst[vi] 

then return failure; 
else i := i + 1; 
end while 
return success; 
end 



Fig. 1. A one-to-one subsumption algorithm 



Following [8] we specialise this general subsumption algorithm Subsume for 
each indexed term t, obtaining its specialized version Subsumet. The specialized 
version has the property Subsumet{q) = Subsume{t,q), for each query term 
q. The specialized algorithm is represented as a sequence of instructions of an 
abstract machine. In other words, we compile the term into code of the abstract 
machine. Then this code is submitted, together with the query term q, to the 
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procedure Subsumet{q) 

begin 



P ■■= A; 


initl : 


: Initialize{li) 


if top(a/p) ^ f return failure; 
p ■— nextq{p)\ 


h : 


Cheek{f, h, faill) 


if tovlaho) ^ 0 return failure: 
p ~ nextq(p)\ 


h : 


Cheek{g, h, faill) 


:= p; 

p ■- after g{p)-, 


h : 


Put(l, I 4 , faill) 


subst[ 2 ] := p; 
p := after ^{p)- 


U : 


Put{2, 15 , faill) 


if tovialv) h return failure; 
p := nextq{p)\ 


h ■ 


Cheek{h, Iq, faill) 


stt6st[3] := p; 
p := after q(p)\ 


Iq : 


Put{3, Ir, faill) 


subst[4] := p; 
p := after q(p)\ 


h '■ 


Put [4, Is, faill) 


if q/subst\V\ q/subst\<i\ return failure; 


h ■ 


Compare{l, 3, Ig, faill) 


if q/subst\V\ q/subst\P\ return failure; 


Ig : 


Compareil, 4, ho, faill) 


return success; 


bo : 


Success 


end 


faill : 


Failure 


Fig. 2. The algorithm Subsume 


Fig. 3. The corresponding sequence 


specialized for the term t = 
f{g{xi,X 2 ),h{xi,xi)) 


of instructions 



interpreting procedure. Before presenting technical details let us consider one 
simple example. 

Example 1. Let t = f(g(xi,X 2 ), h(xi,xi)) be the compiled term. The specialised 
version of the matching algorithm for this term is shown in Figure 2. 

This specialized version can be rewritten in a more formal way using special 
instructions Initialize, Check, Put, Compare, Success and Failure as shown in 
Figure 3. The semantics of these instructions should be clear from the example, 
but will also be formally explained later. 



3.3 Abstract Subsumption Machine 

Now we are ready to describe the abstract machine, its instructions, compilation 
process, and interpretation formally. Memory of the abstract machine is divided 
into the following “registers”: 

1 . substitution register suhst which is an array of positions in the query term; 

2. register p for storing the current position in the query term; 

3. a register instr for storing the label of the current instruction. 
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To identify instructions in code we will use special objects — labels. We dis- 
tinguish two special labels: initl, and faill. A labeled instruction will be written 
as a pair of the form I : I, where I is a label and I is the instruction itself. 
The instruction set of our abstract machine consists of Initialize, Check, Put, 
Compare, Success and Failure. Success and Failure have no arguments. Other 
instruction have the following form: 

— Initialize {I i) , where is a label; 

~ Check{f, h,l2), where / is a function symbol and I2 are labels; 

— Put{n,li,l2), where n is a positive integer and h,l2 are labels; 

— Compare{m,n,li,l2), where m,n are positive integers and l\,l2 are labels. 

For convenience, we define two functions on instructions, cont and hack. On all 
the above instructions cont returns l\ and hack returns I2. Intuitively, cont is the 
label of the instructions that should be executed after the current instruction 
(if this instruction succeeds), and hack is the label of the instruction that is 
executed if the current instruction fails. 

The semantics of the instructions is shown in Figure 4 . At the moment the 
last argument of Put is dummy. It will be used when we discuss the case of many 
indexed terms. 



Initialize{h) p := A; 


Check {s,h,l2) iitop{q/p) = s 


goto ll 


then 




p ~ nextqfp)-. 




goto ll 




else goto I2 


Put[n,h,l2) suhst[n] \= p\ 


Compare{m,n,li,l2) \i q/ subst[m\ = q/ subst[n\ 


p ~ after ^{p)\ 


then goto li\ 


goto ll 


else goto I2 


Success return success 


Failure return failure 



Fig. 4 . Semantics of instructions in code sequences 



For a given indexed term t, compilation of instructions for Subsumct results in 
a set of labeled instructions, called the code for t. It consists of two parts: traver- 
sal code and compare code plus three standard instructions: initl : Initialize {I i), 
sued : Success and faill : Failure. 

Suppose Pi < p2 < ... < Pm are all positions in t. The traversal code for t 
is the set of instructions {h : I\, . . . ,lm ■ Im}, where Ifs, are labels and Ifs are 
defined as follows: 

j _ { Check{top{t / Pi), li+i, faill), if t/pi is not a variable 
\Put{k,k+i, faill), if tsk{t)/pi = *k 




216 



Alexandre Riazanov and Andrei Voronkov 



Let (ui, wi), . . . , (m„, Vn) be the canonical computation sequence for St - Then the 
compare code for t is the set of instructions Im+i ■ Compare{ui,Vi,lm+i+i, faill) 
for z S n}, where Im+n+i = sued. In Figure 3 from example 1 instructions 

h — I7 and Is, I9 form the traversal and compare code correspondingly. 

The code for t is executed on the query term according to the semantics 
of instructions shown in Figure 4 , beginning with the instruction Initialize. It 
is unlikely that the following statement will surprise anybody: execution of the 
code for t on any query term q terminates and returns success if and only if t 
subsumes q. Observe that code for t has a linear structure: instructions can be 
executed sequentially. In view of this observation we will call code for t also the 
code sequence for t. 



3.4 Code Trees for Many-to-One Subsumption 

Recall that our main problem is to find if any term t in a large set T of in- 
dexed terms subsumes a given query term q. Using compilation described in 
the previous subsection, one can solve the problem by the execution of code for 
all terms in T. This solution is inapropriate for large sets of terms. However, 
code sequences for terms can still be useful as we can share many instructions 
from code for different terms. We rely on the following observation: in most in- 
stances in automated theorem proving the set T contains many terms having 
similar structure. Code sequences for similar terms often have long coinciding 
prefixes. It is natural to combine the code sequences into one indexing struc- 
ture, where the equal prefixes of code sequences are shared. Due to the tree-like 
form of such structures we call them code trees. Nodes of code trees are instruc- 
tions of the abstract subsumption machine. Linking of different code sequences 
is done by setting appropriate values to the cont and back arguments of the 
instructions. A branch of such tree is a code sequence for some indexed term in- 
terleaved by some instructions of code sequences for other indexed terms. Apart 
from reducing memory consumption, combining code sequences in one index re- 
sults in tremendous improvements in time-efficiency since during a subsumption 
check shared instructions are executed once for several terms in the indexed 
set. To illustrate this idea let us compare the code sequences for the terms 
h = f{f{xi,X2),f{xi,Xi)) and t2 = f{f{xi,X2),f{x2,X2)). 



initl : Initialize{h) 

11 : Check{f ,l2, faill) 

12 ■ Check(f,l3, faill) 

13 : Put{l, I4, faill) 

I4, : Put{ 2 , 15, faill) 

I5 : Check{f,l&, faill) 
le : Put{ 3 , 17, faill) 

I7 : Put{ 4 :, Is, faill) 

Is : Compare{l, 3 ,ls, faill) 
I9 : Compare{l, 4 :,ho, faill) 
ho ■ Success 



initl : Initialize{h) 
h ■ Check{f,l2, faill) 

12 ■ Check{f,ls, faill) 

13 : Put{l, I4, faill) 

14 : Put{ 2 , h, faill) 

h : Check{f,le, faill) 

Is : Put{ 3 , 17, faill) 

I7 : Put{A, Is, faill) 

Is : Com.pare{ 2 , 3 ,lo, faill) 
Ig : Compare{ 2 ,A,ho, faill) 
bo : Success 




Partially Adaptive Code Trees 217 



Sharing the first eight instructions of this results in the following code: 

C : 

initl : Initialize{l\) 
h : Check{f,l2,faill) 
h : Check{f ,h, faill) 

I3 : Put{l, I4, faill) 

U '■ Put{ 2 , 13, faill) 
h ■ Check{f,l3, faill) 
le : Put{ 3 , 17, faill) 

I7 : Put{A, Is, faill) 

la : Compare{l, 3 ,lg,hi) hi : Compare{ 2 , 3 ,lg, faill) 

Ig : Compare{l,A,ho, faill) I12 ■ Compare{ 2 , 4 ,ho, faill) 
ho ■ Success 

We can execute this code as follows. First, the eight shared instructions are 
executed. If none of them results in failure, we continue by executing instructions 
ls,l9,ho- If the Success instruction ^lo is reached the whole process terminates 
with success. Otherwise, if any of the equality checks ls,lg, failed, we have to 
backtrack and resume the execution from the instruction In. 

In general, to maintain a code tree for a dynamicaly changing set T, one has 
to implement two operations: integration of new code sequences into the tree, 
when a term is added to T, and removal of sequences when a term is deleted 
from T. The integration of a code sequence CS into a code tree CT can be done 
as follows. We move simultaniously along the sequence CS and a branch of CT 
beginning from the Initialize instructions. If the current instruction It in CT 
coincides with the current instruction Is in CS up to the label arguments, we 
skip the instructions following labels in their cont arguments. If It differs from 
Is we have to consider two cases: 

1. If back (It) is not the Failure instruction, in the code tree we move to this 
instruction and continue integration. 

2. If back{lT) is Failure, we set the back argument of It to the label of Is- Thus, 
the rest of the code sequence CS together with the passed instructions in 
CT forms a new branch in the tree. 

Removal of obsolete branches is also very simple: we remove from the code all 
unshared instructions corresponding to the removed term and link the remaining 
instructions in appropriate manner. Due to postponing Compare instructions, 
code trees maitained in this manner have an important property: traversal codes 
for any terms having the same technical skeleton are shared completely. 

Code trees are executed nearly the same way as code sequences, but with 
one difference due to possible backtrack points. As soon as an instruction with 
a backtrack argument is found, we store its backtrack argument and the current 
position in the query term in special stacks backtrPos and backtrinstr. Semantics 
of instructions in code trees is shown in Figure 5 

It is worth noting that all operations in the semantics of instructions can be 
executed very efficiently on fiatterms. 
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Initialize(li) 


P ■■= A; 

backtrPos := empty stack; 
backtrinstr := empty staek; 

goto h 


Check{s, h, h] 


if top{q/p) = s 

then 

pushih, baektrinst); 
push{p, backtrPos); 
p := nextqip); 

goto h 
else goto I2 


Putin, h, I2) 


pushih, baektrinst); 


Compare 


if q/subst[m] = q/subst[n] 




push{p, backtrPos); 
subst[n] := p; 
p ~ after ^{p); 

goto h 


im,n,h,l 2 ) 


then 

push(l2, baektrinst); 
push(p, backtrPos); 

goto h 
else goto I2 


Success 


return success 


Failure 


if backtrPos is empty 
then return failure 
else 

p = pop (backtrPos); 
goto pop (baektrinst) 



Fig. 5. Semantics of instructions in code trees 



To conclude the section we descibe here the differences between this version 
of code trees and that of [8]. These differences make the execution of code trees 
significantly faster: 

1 . The original version of code trees contained 6 more instructions: 

(a) The fiatterm representation of queries made it possible to get rid of the 
stack instructions Push and Pop heavily used in the original version to 
encode term-traversal related operations. 

(b) Effect of the Right and Down instructions is now part of the semantics 
for Check and Put. This saves space and time: instead of fetching two 
instructions we only need to fetch one (instructions are interpreted, so 
there is an overhead in fetching the next instruction) . 

(c) Due to better organization of backtracking, the instructions Fork and 
Restore used for the maintanence of backtracking are not needed any 
more. 

2. The execution of any instruction except Compare requires constant time. The 
most expensive Compare instruction requires comparison of two subterms 
of the query term. Due to the fiatterm representation of the query term. 
Compare instructions are now executed more efficiently. 

4 Partially Adaptive Code Trees 

From the discussion in the previous section the reader could get a feeling that 
code trees are slightly optimized discrimination trees. In this section we discuss 
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an optimization which is essentially impossible on discrimination trees. This 
optimization, partially adaptive code trees, shows greater flexibility of code trees 
as compared to discrimination trees or substitution trees [2,6]. 

It is believed that a greater amount of sharing, and hence efficiency, can 
be gained by using adaptive indexing structures (see [4]). An example of such 
structure is substitution trees [2] or adaptive automata (see [4]). The idea of 
adaptive structures is that the order of the query term traversal is not fixed in 
advance, so indexing structures can adapt themselves to new orders of traversal 
when indexed terms are added or deleted. The price paid for adaptiveness is 
quite high, so it is not clear that adaptive structures can be more efficient than 
the standard ones. The index maintainance becomes more complex, choosing 
a wrong order can actually slow down execution, and it is difficult to ensure 
that the order is good: usually, the problem of optimality of a given structure is 
coNP-complete (see [4]). In the case of code trees for forward subsumption, the 
use of adaptive structures requires tree-like representation of query terms and, 
consequently, a larger set of instructions. 



However, the flexibility of code trees allows one to make them partially adap- 
tive, without changing the order of traversal of query terms. The main idea 
is to use the fact that Compare instructions commute with many other in- 
structions, and thus can be moved up and down the tree (with essentially no 
overhead in the index maintainence). To illustrate this idea, consider the term 
t\ = f{xi,xi,X 2 ,X 2 ) and the following code sequences Ci,C[\ 



Cl : 

initl : Initialize{h) 
h : Check{f,l 2 ,faill) 
h : Put{l, Isjfaill) 

1 3 : Put{2, Ujfaill) 

1 4 : Put{3, l^jfaill) 

Is : Put{4:, ls,faill) 

Is : Compare(l,2,l’j,faill) 
I 7 : Compare{3,4:,ls,faill) 
Is : Success 



C[ : 

initl : Initialize{li) 
h ■ Check{f ,l 2 , faill) 
h ■ Put(l, Isjfaill) 
h ■ Put{2, Ujfaill) 

I 4 : Compare{l,2,ls, faill) 
Is ■ Put{3, Is, faill) 

Is : Put{4, 17 , faill) 

I 7 : Compare{3,4:,ls,faill) 
Is : Success 



The code sequence C\ is computed by our compilation algorithm. The code 
sequence C[ is obtained from Ci by moving the instruction Compare{l, 2, . . .) up 
the sequence. Such a lifting of some Compare instructions serves two purposes. 
The first one is earlier detection of failure. For example, execution of the code 
Cl on the query term q = f{a,b,a,a) determines failure after 7 instructions, 
while C[ fails after 5 instructions. 



The second purpose of moving instructions up the tree is that it can increase 
sharing of code when new code sequences are integrated into code trees. More- 
over, since Compare are potentially expensive instructions, sharing of them is 
especially desirable. For example, consider the term t 2 = f{x\,xi, a, X 2 ) and two 
equivalent code sequences for t 2 '- 
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C2 : 

initl : Initialize{h) 
h : Check{f,l2,faill) 

12 : Put{l, Isjfaill) 

13 : Put{ 2 , Ujfaill) 

14 : Check{a,l5,faill) 

Is : Put{ 3 , le,faill) 

Is : Compare(l, 2 ,l’j,faill) 
h ■ Success 



C'2-. 

initl : Initialize{li) 
h ■ Check{f,l2,faill) 

12 ■ Put{l, l3,faill) 

13 : Put{ 2 , U,faill) 

14 : Compare{l, 2 ,ls, faill) 
Is ■ Checkia, Is, faill) 

Is : Put{ 3 , 17, faill) 
h : Success 



Combining Ci with C 2 gives us the following code tree: 

T : 

initl : Initialize{li) 
h : Check{f,l2, faill) 

12 : Put(l, I3, faill) 

13 : Put{ 2 , 14, faill) 

14 : Put{3,ls,l9) I9 : Check{a, ho, faill) 

Is : Put{ 4 , Is, faill) ho ’■ Put { 2 , 13, faill) 

Is ■ Compare(l, 2 ,h,faiU) hi ■ Compare(l, 2 ,ls, faill) 
h ■ Compare{ 3 , 4 :,ls,faill) 
h : Success 



Combining C[ with C '2 gives us a code tree with less instructions: 
T' : 

initl : Initialize{h) 
h : Cheek{f,l2, faill) 

12 : Put(l, I3, faill) 

13 : Put{ 2 , 14, faill) 

14 : Compare(l, 2 ,ls, faill) 

Is : Put{3,ls,l9) I9 : Cheek{a,ho,fa.ill) 

Is : Put{ 4 ,lr,faill) ho ’■ Put { 2 , 13, faill) 

h : Compare{ 3 , 4 :,ls,faill) 
h : Suceess 



Execution of the code tree T on the query term f{a,b,a,a) fails after 10 
instructions, while execution of T' fails only after 5. 

Under some circumstances, Compare instructions can also be moved down 
the tree, for the same purpose of increasing sharing. We will illustrate this later, 
when we discuss the algorithm of insertion into code trees. Thus, the new code 
trees can adapt themselves to the insertion of new code sequences by moving 
some instructions up and down the tree (but without changing the order of 
traversal of the query term). This is why we call them partially adaptive. 

Apart from moving Compare instructions, other equivalence-preserving trans- 
formations of code sequences can be used to improve sharing. This optimization 
is based on the observation that different computation sequences can be used 
for computing an equivalence relation. When encoding the technical equivalence 
Et by a sequence of Compare instructions we can use any computation sequence 
for Et instead of the canonical one. 
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Example 2. Let us illustrate this idea by an example. Consider the terms ti = 
f{xi,X 2 ,X 2 ,X 2 ) and ^2 = /(a:i, a;i, a;i, 3 ^ 2 ) . The canonical computation sequences 
for Sti and St 2 are (2,3), (2,4) and (1,2), (1,3). The correponding Compare in- 
structions in the code sequences for t\ and t 2 cannot be shared. However, the 
equivalence relation St 2 can be computed by the sequence (2, 3), (1,3), so that 
the instructions Compare {2, 3, . . .) can be shared resulting in the following code 
tree for {ti,t 2 .}' 

initl : Initialize{li) 
h ■ Check{f,l 2 ,faill) 

I 2 ■ Put(l, Zsj/aiZZ) 

Z 3 : Put{2, UjfaiU) 

I 4 : Put{3, Zsj/aiZZ) 

Z 5 : Compare{2,3,le,faill) 

Ze : PmZ(4, Z 7 , Zg) 

Z 7 : Compare(3, 4, Zs,/aiZZ) Zg : Compare{l,3,l8,faill) 

Is : Success 



Note that the semantics of instructions in partially adaptive code trees is the 
same as in the standard code trees. The only difference between the two versions 
of code trees is in their maintenance: the compilation of code sequences and their 
insertion into a code tree. 

Now specialising the algorithm on a given term may produce several differ- 
ent codes. We have to fix a strategy of chosing an appropriate code sequence 
for a given term in presence of a code tree. The choice of the strategy must 
reflect our two main goals: better degree of sharing and earlier detection of fail- 
ure. Moreover, we often have to modify the tree itself significantly since some 
code sequences in the tree are to be adapted to the new code sequences being 
integrated. Thus, the situation is more complex than with the basic version, 
compilation should be done simulataneously with modifying the tree. Our third 
goal is efficiency of maintainence: the insertion into and deletion from code trees 
should be fast. 

In view of the third goal, the deletion algorithm we use in Vampire is very 
simple. After having deleted a code sequence from a tree we do not try to modify 
the trees by shifting Compare instructions. This means that the code tree for a 
set of indexed terms T can change when we insert a code sequence for a new 
indexed term t, and then immediately delete this code sequence. 

We will now focus on the algorithm for insertion into code trees. We do not 
define the algorithm here, but only describe it informally and give an illustrating 
example. The algorithm is similar to the standard insertion algorithm into code 
trees (or discrimination trees), but with the following difference. First, we make 
insertion by ignoring Compare instructions at all. Second, we shift some Compare 
instructions down the tree. Third, we insert remaining Compare instructions 
from the new code. 
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Example 3. Consider a code tree for the set {f{xi,xi,X 2 ,X 2 ),f{xi,xi,a,b)}\ 
initl : Initialize{li) 
h ■ Check{f,l2,faill) 
h ■ Put(l, l3,faill) 

13 : Put{2, Ujfaill) 

14 : Compare(l,2,l3, faill) 

h : Put{3,lQ,lg) I9 : Check{a,ho,faill) 

I3 : Put{4,lr,faill) ho : Check{b,ls,fa.ill) 

h : Compare{3,4:,ls,faill) 

Is : Success 

Suppose that we insert into the set the new term t = f{xi,X 2 ,xi,xi). The code 
sequence for this term consists of the traversal code 
initl : Initialize{m\) 
mi : Check{f,l2,faill) 
m2 : Put{l, l3,faill) 
m3 : Put{2,l4, faill) 
mi : Put{3,ls,fa,ill) 
m3 : Put{4:, lo,faill) 

followed by a sequence of Compare corresponding to a computation sequence for 
the equivalence relation St consising of two classes {1,3,4} and {2}. 

If we ignore the Compare instructions in the code tree, then the nodes 
mi, m 2 , TO 3 , mi, TO 5 would be merged into the nodes respectively. 

But between I 3 and I 4 the tree contains the instruction I 4 : Compare {1, 2, h,faill), 
and (1, 2) does not belong to St- So, we have to move Compare{l, 2, h^faill) down 
the tree. The instruction h : Compare{3,4,ls,faill) can be shared, since (3,4) 
belongs to St- To compute the equivalence relation St, we should add either 
(1,3) or (1,4) to the computation sequence (3,4). So, we obtain the following 
code tree: 

initl : Initialize{h) 



h : Cheek{f,l2,faill) 




I2 : Putil, Isjfaill) 




I3 : Put{2, l3,faill) 




h ■ Put{3, h, hi) 


hi '■ Compare(l,2,lo, faill) 


h ’■ Put{4:,h,faill) 


I9 : Check{a,ho, faill) 


h ’■ Compare{3,4:,l4,faill) 


ho ■ Check{b, Is, faill) 



I4, : Compare{l,2,ls,li2) I12 ’■ Compare{l,3,ls,faill) 
Is : Success 



5 Experiments 

Our experiments have shown that in many cases making code trees partially 
adaptive gives significant reduction of the total number of executed instructions, 
though it may give an increase in the number of executed expensive Compare 
instructions. We compared overall performance of the system with the partialy 
adaptive version of code trees and the basic version on 75 problems from the 
MIX division of CASC-16 [7]. Note that both compared versions are based on 
the flatterms, the old version dealing with tree-like queries is unfortunately not 
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available for comparison. The problems were run with the time limit of 10 min- 
utes on a PC with a Pentium III 500MHz processor. We restricted memory usage 
by 300Mb and the number of kept clauses by 100000. In the table below we give 
times consumed by the optimised version and the basic one {timco and timeh cor- 
respondingly). To make comparison, we calculate percentage of difference (diff) 
between times consumed by the versions w.r.t. the best time. Negative value of 
diff indicates cases when the optimised version showed worse results. From the 
whole benchmark suit 34 problems were selected by the following criteria: (1) 
one of the versions works at least 30 seconds on the selected problems with the 
given limits, (2) absolute value of diff must exceed 1% 



problem 


dtft 


timeo 


timeb 


problem 


dtft 


timeo 


timeb 


alg003-l 


3.33% 


41.13 


42.5 


lcl005-l 


-1.4% 


92.45 


91.17 


alg004-l 


9.86% 


37.9 


41.64 


lcl015-l 


-1.26% 


72.09 


71.19 


boo020-l 


-3.05% 


42.2 


40.95 


lcl016-l 


-1.27% 


71.27 


70.37 


cid003-l 


9.92% 


35.67 


39.21 


lcl017-l 


2.47% 


72.05 


73.83 


cid003-2 


6.36% 


46.97 


49.96 


lcl020-l 


10.74% 


77.41 


85.73 


civ002-l 


-2.54% 


86.59 


84.44 


lcl021-l 


5.28% 


76.89 


80.95 


CO1077-1 


-1.38% 


30.79 


30.37 


lcl099-l 


4.62% 


42.81 


44.79 


Krp054-1 


1.48% 


51.24 


52 


lcll05-l 


4.31% 


39.15 


40.85 


grp073-l 


-1.39% 


34.22 


33.75 


lcll22-l 


1.14% 


80.34 


81.26 


Krp 106-1 


-1.19% 


47.61 


47.05 


lcll25-l 


-1.01% 


36 


35.64 


Krpl07-1 


-1.11% 


70.55 


69.77 


lcll27-l 


3.99% 


57.02 


59.3 


CTP 108-1 


-1.15% 


56.93 


56.28 


lcll29-l 


3.7% 


32.42 


33.61 


grpllO-l 


-1.54% 


40.2 


39.59 


lcll66-l 


5.54% 


77.36 


81.65 


Krplll-1 


-1.1% 


53.86 


53.27 


lcll67-l 


10.48% 


77.26 


85.36 


lat002-l 


-2.53% 


61.13 


59.62 


prv008-l 


9.65% 


166.47 


182.55 


lat005-3 


-1.75% 


61.31 


60.25 


rng025-l 


49.18% 


31.98 


47.71 


lat005-4 


-4.15% 


60.43 


58.02 


rnE034-l 


11.46% 


50.69 


56.5 
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Abstract. This paper proposes a formal framework for argumentative 
dialogue systems with the possibility of counterargument. The framework 
allows for claiming, challenging, retracting and conceding propositions. 
It also allows for exchanging arguments and counterarguments for propo- 
sitions, by incorporating argument games for nonmonotonic logics. A key 
element of the framework is a precise definition of the notion of relevance 
of a move, which enables flexible yet well-behaved protocols. 



1 Introduction 

In recent years, dialogue systems for argumentation have received interest in 
several fields of artificial intelligence, such as explanation [2], AI and law [4, 6], 
discourse generation [5], multi-agent systems [10, 1], and intelligent tutoring [9]. 
These developments justify a formal study of such dialogue systems; this paper 
contributes to this study by an attempt to integrate two relevant developments 
in the fields of argumentation theory and artificial intelligence. 

In argumentation theory, formal dialogue systems have been developed for 
so-called ‘persuasion’ or ‘critical discussion’; see e.g. [8, 14]. In persuasion, the 
initial situation is a conflict of opinion, and the goal is to resolve this conflict 
by verbal means. The dialogue systems regulate the use of speech acts for such 
things as making, challenging, accepting, withdrawing, and arguing for a claim. 
The proponent of a claim aims at making the opponent concede his claim; the op- 
ponent instead aims at making the proponent withdraw his claim. A persuasion 
dialogue ends when one of the players has fullfilled their aim. Logic governs the 
dialogue in various ways. For instance, if a participant is asked to give grounds 
for a claim, these grounds have to logically imply the claim. Or if a proponent’s 
claim is logically implied by the opponent’s concessions, the opponent is forced 
to accept the claim, or else withdraw some of her concessions. 

Although such dialogue systems make an interesting link between the (static) 
logical and (dynamic) dialogical aspects of argumentation, they have one impor- 
tant limitation. The underlying logic is deductive, so that players cannot reply to 
an argument with a counterargument, since such a move presupposes a nonmono- 
tonic, or defeasible logic. Yet in actual debates it is very common to attack one’s 
opponent’s arguments with a counterargument. This is where a recent develop- 
ment in AI becomes relevant, viz. the modelling of nonmonotonic, or defeasible 
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reasoning in the form of dialectical argument games; e.g. [7, 13, 11]. Such games 
model defeasible reasoning as a dispute between a proponent and opponent of 
a proposition. The proponent starts with an argument for it, after which each 
player must attack the other player’s previous argument with a counterargument 
of sufficient strength. The initial proposition is provable if the proponent has a 
winning strategy, i.e., if he can make the opponent run out of moves in whatever 
way she attacks. Clearly, this dialectical setup fits well with the above-mentioned 
dialogue system applications. The main aim of this paper is to incorporate these 
argument games in protocols for persuasion dialogue. This results in a subtype 
of persuasion dialogues that in [11] were called ‘disputes’. 

The following example illustrates these observations. 

Paul : My car is safer than your car. (persuasion: making a claim) 

Olga: Why is your car safer? (persuasion: asking grounds for a claim) 

Paul : Since it has an airbag, (persuasion: offering grounds for a claim; dispute: 
stating an initial argument) 

Olga: That is true, (persuasion: conceding a claim) but I disagree that this 
makes your car safe: the newspapers recently reported on airbags expanding 
without cause, (dispute: stating a counterargument) 

Paul : I also read that report (persuasion: conceding a claim) but a recent scien- 
tific study showed that cars with airbags are safer than cars without airbags, and 
scientific studies are more reliable than sporadic newspaper reports, (dispute: re- 
butting a counterargument, and arguing about strength of conflicting arguments) 
Olga: OK, I admit that your argument is stronger than mine, (persuasion: con- 
ceding a claim) However, your car is still not safer, since its maximum speed is 
much higher, (dispute: alternative counterargument) 

A second aim of this paper is to study the design of argumentative dialogue 
systems. Although most current systems are carefully designed, their underlying 
principles are often hard to see. Therefore, I shall in Section 2 propose a general 
framework for disputational protocols, based on intuitive principles. In Section 3 

1 shall instantiate it with a particular protocol (illustrated in Section 4), after 
which I conclude with a discusison in Section 5. 

2 A Framework for Disputational Protocols 

2.1 Elements and Variations 

In the present framework, the initial situation of a persuasion dialogue is a con- 
flict of opinion between two rational agents about whether a certain claim is 
tenable, possibly on the basis of shared background knowledge. The goal of a 
persuasion dialogue is to resolve this conflict by rational verbal means. The dia- 
logue systems should be designed such that they are likely to promote this goal. 
Differences between the various protocols might be caused by different opinions 
on how this goal can be promoted, but also by, for example, different contexts 
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in which dialogues take place (e.g. legal, educational, or scientific dispute), or by 
limitations of such resources as time or reasoning capacity. 

The present framework fixes the set of participants; two players are assumed, 
a proponent and an opponent of an initial claim. According to [14], dialogue 
systems regulate four aspects of dialogues: 

— Locution rules (what moves are possible) 

— Structural rules (when moves are legal) 

— Commitment rules (The effects of moves on the players’ commitments); 

— Termination rules (when dialogues terminates and with what outcome). 

For present purposes a fifth element must be distinguished, viz. the underlying 
logic for defeasible argumentation. On all five points the framework must allow 
for variations. In particular, the framework should leave room for: 

— allowing one or allowing several moves per turn {unique-move vs. multi-move 
protocols); 

— different choices on whether players can move alternatives to their earlier 
moves {unique-response vs. multi-response protocols); 

— different underlying argument games (but all for justification); 

— various sets of speech acts (but always including claims and arguments); 

— different rules for legality of dialogue moves. In particular, 

• different views on inconsistent commitments 

• automatic vs forced commitment to implied commitments 

— different rules for the effects of moves on the commitments of the players; 

— different termination and winning criteria. 

On the other hand, some conditions are hardwired in the framework. Most im- 
portantly, every move must somehow have a bearing to the main claim. This is 
realised by two other principles: every move must be a reply to some other move, 
being either an attack or a surrender, and every move should be relevant. 



2.2 The Framework 

The framework defines the notion of a protocol for dispute {PPD). 

Definition 1. [Protocols for persuasion with dispute]. A protocol for persuasion 
with dispute (PPD) consists of the following elements. (L, Players, Acts, Replies, 
Moves, PlayerToMove, Comms, Legal, Disputes, Winner), as defined below. 

I now define and comment on each of the elements of a protocol for dispute. 

— Lisa, notion of [11], viz. a protocol for disputes based on a logic for defeasible 
argumentation. wff{L) is the set of all well-formed formulas of L’s language 
and Args{L) the set of all its well- formed arguments. For any set T C wff{L), 
ArgsL{T) C Args{L) are all L-arguments constructible on the basis of the 
input information T. Below, L will often be left implicit. 
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Logics for defeasible argumentation (cf. [12]) formalise nonmonotonic reasoning 
as the construction and comparison of possibly conflicting arguments. They de- 
fine the notions of an argument and of conflict between arguments, and assume 
or define standards for comparing arguments. The output is a classification of 
arguments as, for instance, ‘justified’, ‘defensible’ or ‘overruled’. One way to de- 
fine argumentation logics is, as noted above, in the form of argument games. In 
[11] I showed how these games can be ‘dynamified’ in that the information base 
is not given in advance but constructed during the dispute. For present purposes 
this is very important, since in persuasion dialogues this typically happens. 

The format of both arguments games and protocols for dispute is very similar 
to that of PPD’s. The main elements missing are the set Act and the functions 
Replies and Comms, since these formalisms have no room for speech acts. 

— Players = {P, O}. Player = O iff Player = P, and P iff Player = O. 

— Acts is the set of speech acts, {claim argue{<P, so ip){ C Acts (here, 
^ C wff{L), If G wff{L) and (<?, so ip) G Args{L)). Acts have a performative 
and a content part. Note that each protocol has a claim and an argue act. 

— Replies : Acts — > Pow(Acts) 

is a function that assigns to each act its possible replies. It is defined in terms 
of two other functions of the same type, Attacks and Surrenders. These 
functions jointly satisfy the following conditions. For any A, B G Acts: 

1. B G Replies (A) iS B G Attacks (A) or B G Surrenders (A); 

2. Attacks(A) n Surrenders(B) = 0; 

3. If i? G Surrenders (A), then Replies{B) = 0; 

4. If i? G Attacks(A), then Replies(B) ^ 0. 

Intuitively, an attacking reply is a challenge to the replied-to act, while a sur- 
rendering reply gives up the possibility of attack. For instance, challenging a 
claim, responding to a challenge with an argument for the claim, and stating a 
counterargument are attacking replies, while retracting a proposition in reply to 
a challenge and conceding a proposition in reply to a claim are surrenders. 

— Moves is the set of all well-formed moves. All moves are initial or replying 
moves. An initial move is of the form M\ = {Player, Act), and a replying 
move is of the form Mi = {Player , Act, Move) {i > 1). Player{Mi) denotes 
the first element of a move Mi, Act{Mi) its second element and Move{Mi) 
its third element. If Move{Mi) = Mj, we say that Mi is a reply to, or replies 
to Mj, and that Mj is the target of Mi. 

Now the set Moves is recursively defined as the smallest set such that if 
Player G Players, Act G Acts and Mi G Moves, then {Player, Act) G 
Moves and {Player, Act, Mi) G Moves. 

— PlayerToMove determines the player to move at each stage of a dialogue. Let 
Pow* {Moves) be the set of all finite sequences of subsets of Moves. Then 

PlayerToMove: Pow*{Moves) — > Players 
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such that PlayerT oM ove{D) = P if Z? = 0; else 

1. PlayerToMove{D) = P iff the dialogical status of Mi is ‘out’; 

2. PlayerT oM ove{D) = O iff the dialogical status of Mi is ‘in’. 

The PlayerToMove function is completely defined by the framework: proponent 
begins a dispute and then a player keeps moving until s/he has changed the 
‘dialogical status’ of the initial claim (to be defined below) his or her way. This 
function is hardwired in the framework since the Legal function of the framework 
requires moves to be relevant, and a move will (roughly) be defined to be relevant 
iff it can change the dialogical status of the initial move. Clearly, this does not 
leave room for other PlayerToMove functions than the above one. 

— Comms is a function that assigns to each player at each stage of a dialogue 
a set of propositions to which the player is committed at that stage. 

Comms: P ow* {M oves) x Players — > P ow{wff{L)) . 

such that Comms${P) = Comms${0). 

Note that Commsijjij)) can be nonempty (although it must have the same content 
for P and for O). This allows for an initially agreed or assumed basis for dis- 
cussion. Note also that the framework does not require consistency of a player’s 
commitments. This is since some protocols allow inconsistency, after which the 
other player can demand retraction of one of the sources of inconsistency. 

— Legal is a function that for any dialogue specifies the legal moves at that 
point, given the dialogue so far and the players’ commitments. Let Cp (p G 
Players) stand for Pow{wff {L)) x p. Then 

Legal: Pow* {Moves) x Cp x Co — > Pow{Moves) 

(Below I will usually leave the commitments implicit). 

This function is constrained as follows. For all M G Moves and all D G 
Pow* {Moves), if Mi G Legal{D), then: 

1. If I? = 0, then Mi is an initial move and Act{Mi) is of the form claim {ip)] 

2. Move{Mi) G D; 

3. Act{Mi) is a reply to Act{Move{Mi)); 

4. If Mi and Mj {j < i) are both replies to M^ G D and Mj G D, then 
Act{Mipi) yf Act{Mj); 

5. If Act{Mi) is of the form Argue{A) then Mi’s counterpart in the L- 
dispute Li associated with Di is legal in Lp, 

6. Mi is relevant in D. 

Condition 1 says that a dispute always starts with a claim. Condition 2 says 
the obvious thing that a replied-to move must have been moved in the dialogue. 
Condition 3 says that an act can only be moved if it is a reply to the act moved 
in the replied-to move. Condition 4 states the obvious condition that if a player 
backtracks, the new move must be different from the first move. 
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The last two conditions are crucial. Condition 5 incorporates the underlying 
disputational protocol L, by requiring argue moves to conform to the legality 
rules of this protocol. Li is the proof-theoretical ‘subdispute’ of D in which 
the argue move occurs. Note that thus the framework assumes that with each 
sequence of PPD-moves an L-dispute can be associated. Particular protocols 
must specify the details. 

Finally, Condition 6 every move to be relevant. Relevance, to be defined 
below, is the framework’s key element in allowing maximal freedom (including 
backtracking and postponing replies) while yet ensuring focus of a dispute. 

— Disputes is the set of all sequences Mi, . . . , M„ of moves such that for all i: 

1. Player{Mi) = PlayerToMove{Mi , . . . , 

2. Mi G Legal{Mi, . . . , Mi-i). 

— Winner is a function that determines the winner of a dialogue, if any: 
Winner: Disputes — > Players 

The winning function is constrained by the following condition. 

• If Winner{D) = p, then PlayerToMove{D) = p and Legal{D) = 0; 

Thus, to win it must hold that the other player has run out of moves. The 
rationale for this is the relevance condition (to be defined next); as long as a 
player can make relevant moves, s/he should not be losing. Note that termination 
is defined implicitly, as the situation where a player-to-move has no legal moves. 

I now turn to relevance. This notion is defined in terms of the dialogical 
status of a move (either ‘in’ or ‘out’), which captures whether its mover has 
been able to ‘defend’ the move against attacks. A move can be in in two ways: 
the other player can have conceded it, or all attacks of the other player have 
been successfully replied to (where success is determined recursively). As for 
conceding a move, the general framework only states two necessary conditions: 

— If a move M is conceded in D, then it has a surrendering reply in D. 

— If M is conceded in D, it is conceded in all continuations of D. 

The reason why these conditions are not sufficient lies in the most natural treat- 
ment of replies to arguing moves. In Section 3 we shall see that an arguing move 
has several elements (premises, conclusion, inference rule), some of which can 
be surrendered but others attacked at the same time. Therefore the notion of 
conceding a move must be fully defined in particular dialogue systems. 

Definition 2. [Dialogical status of moves] A move M of a dialogue D is either 
in or out in D. It is in in D iff 

1. M is conceded in D; or else 

2. all attacking moves in D that reply to it are out in D. 

Now a move is relevant iff any attacking alternative would change the status of 
the initial move of the dialogue. This can be captured as follows. 
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PI + pj + pj - 

or or 01^ 




04 is irrelevant 04’ is relevant 



Fig. 1. Dialogical status of moves. 



Definition 3. [Relevance.] A move in a dialogue D is a relevant target iff any 
attacking reply to it changes the dialogical status of D ’s initial move. A move is 
relevant in D iff it replies to a relevant target in D. 

Note that a reply to a conceded move is never relevant. 

To illustrate these definitions, consider figure 1 . The first dispute tree shows 
the situation after P4. The next tree shows the dialogical status of the moves 
when O has continued with replying to P3: this move does not affect the status 
of Pi, so O4 is irrelevant. The final tree shows the situation where O has instead 
replied to P4: then the status of Pi has changed, so O4 is relevant. 

3 An Instantiation of the Framework 

To illustrate the general framework, I now instantiate it with a specific protocol. 



The Underlying Disputational Protocol The disputational protocol L is 
that of liberal disputes as defined in [11], instantiated with proof-theoretical 
rules for sceptical argumentation. Liberal disputes allow an argument as long as 
it is relevant. In [ 11 ] it is shown that this protocol satisfies certain ‘soundness’ 
and ‘fairness’ properties with respect to the underlying argumentation logic. 

Besides a set Args of constructible arguments, L also assumes a binary re- 
lation of defeat among arguments. An argument strictly defeats another if the 
first defeats the second but not the other way around. Now Dung’s argument 
game says that proponent begins with an argument and then players take turns 
as follows: proponent’s arguments strictly defeat their targets, while opponent’s 
arguments defeat their targets. In addition, proponent is not allowed to repeat 
his moves in one ‘dialogue line’ (a dispute without backtracking moves). The 
precise definition of the notions of an argument, conflict and comparison of ar- 
guments are not essential, and therefore I keep these elements semiformal, using 
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obvious logical symbols in the examples, with both material (d) and defeasible 
(=i>) implication. But the protocol assumes that arguments can be represented 
as a premises-conclusion pair <I>, so <^, where <P C wff{L) are the premises and 
ip € wff{L) is the conclusion of the argument. 

Speech Acts The set of speech acts is defined as follows. 



Acts 


Attacks 


Surrenders 


claim p 


why p 


concede p 


why p 


argue <L, so p 


retract p 


concede p 






retract p 






argue{d>, so p) 


why Pi {pi& <P) 
argue {d>' , so p') 


concede pi [pi G 'P) 
concede{<P implies p) 


concede{<P implies p) 







Here C wjf{L), ip,ip' e wff{L), and (<?, so ip) and {<P' , so ip') G Args{L). 

The claim, why, retract and concede ip moves are familiar from MacKenzie- 
style dialogue systems. The argue move is present in e.g. [4] and [14]. The conced- 
ing an inference move is adapted from [4]. Its effect is to give up the possibility 
of counterargument. Note that an argument can be replied to by replying to one 
of its premises or to its inference rule, or by a counterargument. 

Commitment Rules The commitment rules are as follows. Let Di = 
Ml, . . . ,Mi be any sequence of moves, and let Player(Mi) = p. 

— If Act{Mi) = claim ip or concede p, then CommsDiip) = CommsDi_i{p) U 

{rf- 

— If Act(Mi) = argue{d>, so p), then CommsDi{p) = CommsDi_i{p)^d>\j{p'\. 

— If Act{Mi) = retract p then CommsDi{p) = CommsDi-Av) /{p}- 

— In all other cases the commitments remain unchanged. 

The effects of claims, concessions and retractions are obvious. As for the ef- 
fects of moving arguments, note that their conclusion is not also added to the 
mover’s commitments. This is since some dialectical proof theories, including 
the present-used one, sometimes allow a player to attack himself. In [14] the 
material implication is also added to the commitments of the argument’s mover. 
Although this works fine if the underlying is monotonic, in the present approach, 
which allows defeasible arguments, this is different. 

Legality of Moves The definition of the Legal function is completed as follows. 
For all M G Moves and all D G Pow* {Moves), Mi G Legal {D) iff the above 
conditions and the following conditions are satisfied. 

7. Each move must leave the mover’s commitments classically consistent; 

8. If Act{Mi) = concede p, then 

(a) Comms Di-i{Plo,yeri) [/ p; 

(b) Comms Di-i{PlayeTi) do not justify ^p; 
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9. If Act{Mi) = retract ip, then 

(a) ip G CommsDi-iiPlaysTj); and 

(b) ip was explicitly added to CommsDi-i{PlayeTj}. 

10. If Act{Mi) = why ip, then Comms Di-i{Pl<iyer j) do not justify ip. 

11. If Act{Mi) = argue{<P, so ip), then 

(a) all preceding moves Mj G D with Act{Mj) = why ipi {ipi G <?) are out] 

(b) If Mi replies to an argue move Mj, then Mj has no child concede{<P, so 

ip). 

As for Condition 7, note that a commitment set which supports two conflicting 
defeasible arguments does not have to be classically inconsistent. Whether it is, 
depends on the underlying logic for constructing arguments. Many logics allow 
the consistent expression of examples like ‘Tweety is a bird, birds generally fly, 
but Tweety does not fly’. This enables such moves as “I concede your argument 
as the general case, but in this case I have a counterargument . .” 

Condition 8a says that a proposition may only be conceded if the mover 
is not committed to it. (This allows conceding a proposition that is defeasibly 
implied by the player’s own commitments.) Condition 8b forbids conceding a 
proposition if the opposite is justified by the player’s own commitments. 

Condition 9 is obvious. Condition 10 allows retractions of ‘explicit’ commit- 
ments only. This forces a player to explicitly indicate how an implied commit- 
ment is retracted. Condition 11a forbids moving arguments of which the premises 
are under challenge. This is [8]’s way to avoid arguments that “beg the ques- 
tion”. Finally, Condition 11b says that if an argument was already conceded, no 
counterargument can be stated any more. 



Conceding a Move Next I complete the definition of conceding a move. 

Definition 4 (Conceding a move). A move M in a dialogue D has been 
conceded iff 

— Act{M) yf argue(A) and M has a surrendering child; or 

— Act{M) = argue(A) and both all premises and the inference rule of A have 
been conceded. 



Associated i-Disputes Next the notion of an L-dispute associated with a 
PPD-dispnte must be defined. This notion is used in determining legality of 
counterarguments, but it can also serve to study logical properties of winning 
criteria. The idea is that during a PPD-dispute an L-dispute of arguments and 
counterarguments is constructed. A technical problem is that argue replies to 
why moves extend an argument backwards, by replacing one of its premises with 
an argument for this premise. To account for this, we must first define the notions 
of a combination of two arguments and of a modification of an argument. 

Definition 5. [Combinations of arguments.] Let {A = S, so ip) and {B = S' , 
so Ip) be two arguments such that ip G S. Then A® B = {S/{ip}) U S' , so ip. 
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Definition 6. [Modification of arguments.] For any arguments A, B and C , A 
is a modification of A; if B is a modification of A and B ® C is defined, then 
B ® C is a modification of A; nothing else is a modification of A. We also say 
that A modifies A, and B modifies A in A® B. And an argue move modifies 
another argue move if the argument moved by the first modifies the argument 
moves by the second move. 

For any move M = {p, a, m) and arguments a and b, M[a/b] = (p, argue{b), m) 
if a = argue{a); otherwise M[a/b] = M. Likewise for initial moves. 

Now the notion of the L-part of a dispute can be defined. 

Definition 7. [L-disputes of a PPD-dispute.] For any PPD-dispute D, the 
associated L-dispute L{D) is a sequence of argue moves defined as follows. 

1 . T(0) = 0; 

2. If Act{Mi+i) yf argue{A) for any A, then T{Di+i) = T{Di); 

3. If Act{Mi+i) = argue(A) for some A, then 

(a) If Mi+i replies to an argue move Mj, then T{Di+i) = T{Di), 

where is except that it replies to the move in T{Di+i) mod- 

ified by Mj; 

(b) If Mi+i = {p,a,m) replies to a why move replying to a claim, then 

T(A+i)=T(A),(p,a); 

(c) If Mi+i replies to a why ip move replying to an argue(B) move Mj, then 

i. If Ti contains any argue moves Mk resulting from modifications 
of Mj such that their arguments C still have a premise p, then 
T{Dij.i) = T*{Di), where T*{Di) is obtained from T{Di) by re- 
placing C in all such Mk with C (S> A, and then adjusting the targets 
of moves when these targets have been changed, 
a. Else T(Di+i) = T{Di), Mj, where M[ is obtained from Mj by re- 
placing B with B ® A. 

So the construction of an L-dispute starts with the empty set, and each PPD- 
move other than an argue move leaves its content unchanged. As for argue PPD- 
moves, two cases must be distinguished, whether it replies to another argue move 
or to a why move. In the first case the argue move can simply be added to 
the L-dispute, but the second case is more complex. Again two cases must be 
considered. If the replied-to why move itself replied to the initial claim, then 
the argue is the root of a new dialectical tree, so the move to which it replies 
must be omitted, to turn it into an initial move. Finally, if the replied-to why tp 
move challenged the premise of an argument B, then again two cases must be 
considered. If the L-dispute contains modifications of A that still contain premise 
ip, then these modifications (if not equal to B itself) were triggered by a why 
attack on another premise of L. In that case ip must in all these modifications 
be replaced with the premises of A. Note that if no such other why attacks were 
made, this boils down to modifying B itself. (Note also that if in T, Mi replies 
to Mj, and Mj is then modified by Mk, from then on Mi replies to the modified 
move.) If, however, no modification of B in the L-dispute contains a premise ip. 
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then moving A was an alternative to an earlier reply to the why ip move. Then we 
must add to the L-dispute an alternative modification of the original argue(B) 
move, with B ® A (note that the original move was not in Ti any more). 

In general an L-dispute is a collection of trees, since a why reply to the initial 
move can be answered with alternative arguments. So the condition of the general 
framework that an argue move M is legal in the associated L-dispute means that 
M is legal in the tree contained in this dispute that itself contains Move{M). 

Winning As for winning, several definitions are conceivable. Part of the aim of 
the present framework is to provide a setting in which the alternatives can be 
compared. In the present protocol I simply turn the necessary conditions of the 
general framework into a necessary-and-sufficient condition. 

Definition 8. For any dispute D, Winner{D) = p iff Player To Move{D) = p 
and Legal{D) = 0 . 

It is immediate that if p wins D, then Mi in D is labelled p's way. However, the 
same does not always hold for the associated L-dispute. Consider the following 
dispute D (In the examples below I leave the replied-to move implicit if it is the 
preceding move, and Pi and Oi stand for turns of a player.) 

P \ : claim p 0 \ : why p 

P2'. argue{q, q ^ p, so p) O2' argue{q, r,q Ar ^ ^p, so ^p) 

P3: why r O3: concede p (to Pi) 

Now P has won, but T{D) = P2, O2, in which P2 is out and O2 is in. So a player 
can lose by unforced surrenders. 

It also holds that if O has won, P is not committed to his main claim any 
more. This is since if all other moves have become illegal for P, he can still 
surrender to O’s initial why attack. However, it does not hold that if P has won, 
O is always committed to P’s main claim p. This is since O might have moved 
an argument with premise and in the course of the dispute retracting p may 
have become irrelevant and thus illegal, so that conceding Mi has also become 
illegal. Future research should reveal whether this is a problematic property of 
the protocol. 

4 Examples of Dialogues 

Example 1 . Most argumentation logics do not allow counterarguments to deduc- 
tively valid arguments. If such a logic underlies our protocol, then conceding the 
premises of such an argument can cause a loss. Consider 

Pi : claim p Oi : why p 

P2: argue{q, q D p, so p) O2' concede q, concede q D p 

Now O is still to move, and her only legal moves are concede{{q, qAp} implies 
q) and concede p, after which moves Pi is still in so O cannot move. 




On Dialogue Systems with Speech Acts, Arguments, and Counterarguments 235 



Example 2 . The next example (on the Nixon diamond) shows that a player can 
lose with a poor move even if the player’s own commitments support a valid 
counterargument. Suppose Comms${p) = {Qx ^ Px^Qn} and consider 

Pi: claim ^Pn Oi: why ^Pn 

P2: argue{Rn, Rx => so ^Pn) O2: concede Rn, concede Rx ^ ^Px, 

concede ~^Pn (to Pi). 

Now P wins while O could instead of conceding Pi have attacked it with ar- 
gue{Qn, Qx ^ Px, so Pn). Note also that if O had not conceded P2’s premises, 
then conceding ^Pn would have violated condition 8b on move legality. 

Example 3 . The next dispute shows that a player can sometimes use the other 
player’s commitments against that player (the commitments are shown each time 
when they have changed). 



Move 


CommsD{P) 


CommsoiO) 




{s -ig, r At ^ p} 


{s -ig, r At ^ p} 


Pi: claim p 


{s -ig, r At ^ p,p} 




Oi: why p 






P2: argue{r, s,r A s ^ p, so p) 


{s -ig, r At ^ p,p, 
r, s,r A s ^ p} 




O2: concede r, 

argue{q, q ^ ^ -is, so ~<s) 




{s -ig, r At ^ p,q,r 

q =A t,t —IS, —is} 



At this point, O’s commitments justify p, since they contain an implicit argu- 
ment for p. Suppose P next moves this argument. Then O can in turn use a 
counterargument supported by P’s commitments. 



P3: argue{r, q,q ^ t, 
r At ^ p, so p) 




{s ^g, r At ^ p,p, 
r, s,r A s ^ p, 
r,t,q^ t} 




O3: argue{s, s ^g. 


so ^g) 




{s ^g, r At ^ p,q,r 

q ^ t,t ^ ~^s, ^s} 



And the dispute continues. 

Example 4 - Next I illustrate the construction of an P-dispute. I first list a PPD- 
dispute and then the construction of the associated P-dispute. 

Pi : claim p Oi : why p 

P2: argue{q, q ^ p, so p) O2: argue{r, r ^p, so ^p) 

P3: argue{s, t, s At ^ p, so p) (P3 jumps back to Oi) 

O3: why s 

P4: argue{u,u s, so s) O4: argue(v,v ~^u, so ^u) 
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P5: argue{x,x s, so s) (P5 jumps back to O3) 

O5: argue{y,y ^x, so ^x) 

Pq: argue{z,z -r, so ^r) {Pq jumps back to O2) 

(Oe jumps back to P3) Oq: why t 
P7: argue{k, k ^ t, so t) 

The associated L-dispute is constructed as follows. The first two arguments are 
added with P2 and O2, so (denoting disputes with their last move and listing 
the replied-to moves between square brackets): 

T(P2) = P2 
T{02) = P2,02{P2] 

So far, T contains just one dialectical tree. A second tree is created by P3, which 
is an alternative argue reply to O's why attack on P’s main claim. Hence 

T(P 3 ) = P 2 , 02 [P 2 ],P 3 

With P4 the first modification of an argument in T takes place. P3’s argument 
is combined with P4’s argument for s (displayed with overloaded ®). 

T(P4) = P2,O2[P2],P3 0P4 

O4 simply adds a new argument, which replies to P3 as modified by P4. 

T{Oi) = P2, 02[P2], P3 0 P4, 04[P3 0 Pa] 

P5 splits the second tree in T into two alternative trees, by giving an alternative 
backwards extension of its root. Then O5 simply extends the newly created tree, 
after which Pq extends the first tree in T. 

T(Ps) = P 2 , 02 [P 2 ], P 3 (g) Pa, Oa[P3 ® P 4 ], P 3 0 P 5 

T{ 0 ^) = P2, 02[P2], P3 0 Pa, Oa[P^ ® P4], P3 0 P5, ^^5] 

T(Pe) = P2 , 02 [P 2 ] , Pe [O2] ,Ps^Pa,Oa [P3 0 P4] ,Pz®P^,0^ [P3 0 P5] 

Finally, P7 illustrates an interesting phenomenon. It replaces the second premise 
of O3 with an argument; however, O3 was already modified twice in two alterna- 
tive ways with respect to its first premise, so P7 actually modifies both of these 
modifications of O3. This results in the following final P-dispute. (Note also that 
the targets of O4 and O5 have been replaced with their extended versions.) 



P2- 






q, 




so p 








O2: 






r. 


r => 


^p. 


so 


[P2] 






PP- 






z. 


z ^ 


-nr. 


so 


[O2] 






P3® 


Pa 


0 P7: 


u, 


, u => 


s, k. 




t,s At 


^P, 


SO p 


P3® 


P5 


0 P7: 


X, 


, X => 


s, k. 


,k 


t,s At 


^P, 


so p 


O4: 






V, 


V => 


-nu, 


so 


-nu [P3 (g) 


Pa 0 


07] 


O5: 






y, 


y 


-nx, 


so 


^X [P3 (g) 


P5 0 


07] 
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5 Discussion 

Alternative Instantiations To discuss some alternative instantiations of the 
framework, note first that alternative definitions of winning may be possible, for 
instance, in terms of what is implied by the players’ commitments. Secondly, as 
for maintaining consistency of one’s commitments, some protocols allow incon- 
sistency but give the other party the option to demand resolution of the conflict; 
a similar resolve move is possible if a commitment is explicitly retracted but 
still implied by the remaining commitments [8, 14]. Thus the burden of proving 
inconsistency or implicit commitment is placed upon the other party. Finally, as 
for replies to why moves, the obligation to reply to it with an argument for the 
challenged claim could be made dependent on questions of the burden of proof. 



Features and Restrictions of the Framework The framework of this paper 
is flexible in some respects but restricted in some other respects. It is flexible, 
firstly, since it allows for different sets of speech acts, and different commitment 
rules, underlying logics and winning criteria. It is also ‘structurally’ flexible, in 
that it allows for backtracking, including jumping to earlier branches, and for 
postponing replies to move (even indefinitely if the move has become irrelevant). 
This flexibility is induced by the notion of relevance. 

However, the framework also has some restrictions. For instance, the condi- 
tion of relevance prevents the moving in one turn of alternative ways to change 
the status of the main claim. Further, the requirement that each move replies 
to a preceding move excludes some useful moves, such as lines of questioning 
in cross-examination of witnesses, with the goal of revealing an inconsistency in 
the witness testimony. Typically, such lines of questioning do not want to reveal 
what they are aiming at. The same requirement also excludes invitations to re- 
tract or concede [8, 14]. Finally, the framework only allows two-player disputes, 
leaving no room for, for example, arbiters or judges. 



Related Research There have been some earlier proposals to combine formal 
dialogue systems with argumentation logics. Important early work was done by 
Loui [7], although he focussed less on speech act aspects. A major source of 
inspiration for the present research was Tom Gordon’s model of civil pleading 
in anglo-american law [4] (cf. also [6]). Gordon presents a particular protocol 
rather than a framework. The same holds for a recent proposal in the context of 
multi-agent negotiation systems [1]. Finally, [3] shows how protocols for multi- 
party disputes can be formalised in situation calculus. Brewka focuses less on 
dialectical and relevance aspects but more on describing the ‘current state’ of a 
dispute and how it changes. His approach paves the way for, for instance, formal 
verification of consistency of protocols. 



Conclusion This paper has presented a formal framework for persuasion dia- 
logues with counterargument, and has given one detailed instantiation. Unlike 
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earlier work, the framework is based on some general design principles, notably 
the distinction of attacking and surrendering replies to a move, and the notions 
of dialogical status and relevance of moves. The framework’s instantiation also 
provided a still generic notion of an argument-counterargument dispute associ- 
ated with a persuasion dialogue; I expect that this notion will provide a basis 
for investigating logical properties of the protocol, especially of its winning con- 
ditions. 

Being a first attempt to provide a general framework, the focus of this paper 
has been more on definition than on technical exploration. Much work needs to 
be done on investigating its properties. In fact, one aim of this paper was to 
make this further work possible. 
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Abstract. This paper presents dialectical proof theories for Dung’s pre- 
ferred semantics of defeasible argumentation. The proof theories have the 
form of argument games for testing membership of some (credulous rea- 
soning) or all preferred extensions (sceptical reasoning). The credulous 
proof theory is for the general case, while the sceptical version is for 
the case where preferred semantics coincides with stable semantics. The 
development of these argument games is especially motivated by applica- 
tions of argumentation in automated negotiation, mediation of collective 
discussion and decision making, and intelligent tutoring. 



1 Introduction 

An important approach to the study of nonmonotonic reasoning is that of logics 
for defeasible argumentation (for an overview see [25]). Within this approach, 
a unifying perspective is provided by the work of [9] and [4] (below called the 
‘BDKT framework’). It takes as input a set of arguments ordered by a binary 
relation of ‘attack’, and it produces as output one or more ‘argument extensions’, 
which are maximal (in some sense) sets of arguments that survive the compe- 
tition between all input arguments. A definition of argument extensions can be 
regarded as an argument-based semantics for defeasible reasoning. BDKT have 
developed various alternative such semantics, and investigated their properties 
and interrelations. They have also shown how many nonmonotonic logics can be 
recast in their framework. Thus their framework serves as a unifying framework 
not only for defeasible argumentation but also for nonmonotonic reasoning in 
general. 

The BDKT framework exists in two versions. The version of [9] completely 
abstracts from the internal structure of arguments and the nature of the attack 
relation, while the version of [4] is more concrete. It regards arguments as sets of 
assumptions that can be added to a theory formulated in a monotonic logic in 
order to derive defeasible conclusions, and it defines attack in terms of a notion 
of contrariness of assumptions. 

Besides a definition of argument-extensions, it is also important to have a test 
for extension membership of individual arguments, i.e., to have a proof theory 
for the semantics. A natural (though not the only) form of such proof theories 
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is the dialectical form of an argument game between a defender and challenger 
of an argument [18, 29, 8, 5, 26, 24, 14]. The defender starts with an argument 
to be tested, after which each player must attack the other player’s arguments 
with a counterargument of sufficient strength. The initial argument is provable 
if its defender has a winning strategy, i.e., if he can make the challenger run out 
of moves in whatever way she attacks. The precise rules of the argument game 
depend on the semantics which the proof theory is meant to capture. 

For [4]’s assumption-based version dialectical proof theories have been studied 
by [15]. However, for [9]’s abstract version only the so-called ‘grounded (sceptical) 
semantics’ has been recast in dialectical style, viz. by [8]. Grounded semantics 
is sceptical in the sense that it always induces a unique extension of admissible 
arguments: in case of an irresolvable conflict between two arguments, it leaves 
both arguments out of the extension. For the other semantics of [9], which in case 
of irresolvable conflicts all induce multiple extensions, dialectical forms must still 
be developed. This paper contributes to this development: it presents a dialectical 
argument game for perhaps the most important multiple-extension semantics of 
[9], so-called preferred semantics. In fact, we shall present two results: a proof 
theory for membership of some preferred extension (credulous reasoning) and the 
same for membership of all preferred extensions {sceptical reasoning, although 
only for the case where preferred semantics coincides with stable semantics). 

It should be motivated why proof theories for the most abstract version of the 
BDKT framework are important besides their counterparts for the assumption- 
based version. Kakas & Toni’s work is very relevant when arguments can be 
cast in assumption-based form. In many applications this is possible, but in 
other applications this is different. For instance, argumentation has been used 
as a component of negotiation protocols, where arguments for an offer should 
persuade the other party to accept the offer [16, 20]. Argumentation is also 
part of some recent formal models and computer systems for dispute mediation 
[10, 11, 6], and it has been used in computer programs for intelligent tutoring: 
for instance, in a system (Belvedere) that teaches scientific reasoning [27] and 
in systems that teach argumentation skills to law students, e.g. [l]’s CATO 
system and [28] ’s ARGUE system. Now in many applications of these types, 
arguments have a structure that cannot be naturally cast in assumption-based 
form. For instance, they can be linked pieces of unstructured natural-language 
text (cf. Belvedere or Gordon’s ZENO system), or they consist of analogical uses 
of precedents, such as CATO’s arguments. It is especially for such applications 
that proof theories for [9]’s abstract framework are relevant. 

It should also be motivated why a proof-theory for preferred semantics is im- 
portant despite the pessimistic results on computational complexity recorded 
by [7]. To start with, these pessimistic results concern worst-case scenarios, and 
cases might be identified where computation of preferred semantics is still fea- 
sible. Moreover, as demonstrated by e.g. [21, 18], logics for defeasible argumen- 
tation provide a suitable basis for resource-bounded reasoning: dialogues corre- 
sponding to such logics can be interrupted at any time such that the intermediate 
outcome is still meaningful. Finally, there is a possible use of argument-based 
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proof theories which does not suffer from the computational complexity, viz. in 
automated mediation and tutoring. In, for instance, mediation systems for nego- 
tiation or collective decision making, and also in systems for intelligent tutoring, 
the search for arguments and counterarguments is not performed by the com- 
puter, but by the users of the system, who input their arguments into the system 
during a discussion. In such applications the argument-based proof theory can 
be used as a protocol for dispute: it checks whether the users’ moves are legal, 
and it determines given only the arguments constructed by the users, which of 
the participants in a dispute is winning. (See e.g. [23] for a logical study of this 
use of dialectical proof theories). 

Finally, we must motivate why argument-game versions are important besides 
other argument-based proof theories, such as [21] ’s proof theory for his system, 
which is based on preferred semantics. This has to do with applications in fields 
like mediation and tutoring. In these fields, argumentation has been used as 
a component of several computational dialogue systems based on speech acts, 
such as models of legal procedure, [10, 13, 3, 17], discourse generation systems 
[12], multi-agent negotiation systems [20, 2], and intelligent tutoring [19]. In our 
opinion, the dialectical form of an argument game is ideally suited for embedding 
in such dialogue systems (see [22] for a formal study of such embeddings) . 

The structure of this paper is as follows. In Section 2 we provide an overview 
of the basics of the BDKT framework. In Section 3 we discuss with the help of 
examples which features our argument games should have. Then we define the 
credulous argument game in Section 4 and the sceptical game in Section 5, after 
which we discuss some limitations in Section 6. 

2 Definitions and Known Results 

In this section we review the basics of the BDKT framework, as far as needed 
for present purposes. The input of the system is a set of arguments ordered by 
an attack relation. 

Definition 1. (Argument system [9]). An argument system A is a pair 

A={X,^), (1) 

where X is a set of arguments, and ^ is a relation between pairs of arguments 
in X . The expression a ^ b is pronounced “a is attacked by b, ” “b is an attacker 
of a,” or “b is a counterargument of a”. 

Example 1. The pair A = {X,<—) with arguments 

X = {a, 6, c,d,e,f,g,h,i,j,k,l,m,n,p, q} 

and <— as indicated in Figure 1 is an (abstract) example of an argument system. 
It accommodates a number of interesting cases and anomalies, and will therefore 
be used as a running example throughout this paper. 
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Fig. 1. Attack relations in the running example. 



In practical applications it is necessary to further specify the internal structure 
of the arguments and the relation See e.g. [30]. However, for the purpose of 
this paper it not necessary to do so; at present it suffices to know that there are 
arguments, and that some arguments attack other arguments. 

The output of the system is one or more argument extensions, which are sets 
of arguments that represent a maximally defendable point of view. The different 
semantics of the BDKT framework define different senses of ‘maximally defend- 
able’. We list the definitions of two of them, stable and preferred semantics. 

1. An argument a is attacked by a set of arguments B li B contains an attacker 
of a. (Not all members of B need attack a.) 

2. An argument a is acceptable with respect to a set of arguments C, if every 
attacker of a is attacked by a member of C: for example, if a <— 6 then b *— c 
for some c G C. In that case we say that c defends a, and also that C defends 
a. 

3. A set S of arguments is conflict-free if no argument in S attacks an argument 
in S. 

4. A conflict-free set S of arguments is admissible if each argument in S is 
acceptable with respect to S. 

5. A set of arguments is a preferred extension if it is a C-maximal admissible 
set. 

6. A conflict-free set of arguments is a stable extension if it attacks every ar- 
gument outside it. 

The following results of [9] will be used in the present paper. 

Known results, (from [9]) 

1. Each admissible set is contained in a Q-maximally admissible set 

2. Every stable extension is preferred. 

3. Not every preferred extension is stable. 

4 . Stable extensions do not always exist; preferred extensions always exist. 

5. Stable and preferred extensions are generally not unique. 
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3 The Basic Ideas Illustrated 

In this section we discuss with the help of examples which features our argument 
games should have. 

Our game for testing membership of some extension is based on the following 
idea. By definition, a preferred extension is a C-maximal admissible set. It is 
known that each admissible set is contained in a maximal admissible set, so 
the procedure comes down to trying to construct an admissible set ‘around’ the 
argument in question. If this succeeds we know that the admissible set, and 
hence the argument in question, is contained in a preferred extension. 

Suppose now we wish to investigate whether a is preferred, i.e., belongs to 
a preferred extension. We know that it suffices to show that the argument in 
question is admissible. The idea is to start with S = {a}, which most likely is 
not admissible. (Because S is small, and small sets are usually conflict-free but 
not admissible.) So other arguments must be found (or constructed) in order to 
complete S into an admissible set. 

Procedure. (Constructing an admissible set). Let a he an argument for which 
we try to construct an admissible set. This task can best be divided in two sub- 
tasks: 

Task 1: Let us suppose this task is performed by person PRO, who assumes 

construe- a constructive role by trying to show that a is contained in an ad- 

tion. missible set. To this end, PRO examines if there are arguments that 

attack his arguments constructed thus far. Lf there is such an ar- 
gument, PRO tries to attack it by trying to construct an argument 
that attacks the original attacker (acceptability). Lf PRO has found 
such an argument, it must be consistent with his previous arguments 
( conflict- freeness) . 

pro’s role is purely defensive: his goal is to incorporate defenders against at- 
tacks constructed thus far — not to extend his collection of arguments per se. To 
the contrary, in fact: PRO’s goal is to keep his collection of arguments as small 
as possible, because PRO is more vulnerable if he (or she)^ has more arguments 
to defend. 

Task 2: This task is performed by person CON, who assumes a critical role 

criti- by trying to find counterarguments to arguments advanced by PRO. 

cism. In a way, CON’s aim is to ‘make PRO talk’ in the sense that PRO 

is more vulnerable if he has more arguments to defend. 

The procedure formulated here is not necessarily adversarial: one way to look 
at it is to say that CON helps PRO by attending him to arguments that might 
invalidate PRO’s collection of admissible arguments. 

From here on we will use the generic masculine form, intending no bias. 



1 
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Example 2. (Straight failure). Consider the argument system that was presented 
at the beginning of this paper. Suppose PRO’s task is to show that a is preferred. 
Since preferred extensions are maximally admissible sets it suffices for PRO to 
show that a is admissible, i.e., that a is contained in an admissible set. 



The first action of PRO is 
simply putting forward a: 



C 



a 



If a can’t be criticized, i.e., if there are no attackers, then S = {a} is admissible, 
and PRO succeeds. However, since a ^ h, 



CON forwards h: h 




Now it is up to PRO to defend a by finding arguments against h. There are no 
such arguments, so that PRO fails to construct an admissible set ‘around’ a. So 
a is not admissible, hence not preferred. 



Example 3. (Straight success). Suppose that PRO wants to show that b is ad- 
missible. 



The first action of PRO is 
putting forward b: 




CON attacks b with d: 



d 




d 





9 



PRO defends this attack 
with g: 
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Since CON’s attack on b 
with d has failed, CON 
returns to b and attacks it 
again, this time with e: 

PRO defends b again, this 
time with h. Since CON is 
unable to find other 
argument against 6, g or h, 
PRO may now close S: 




Example 4- (Even loop success). Suppose that PRO wants to show that / is 
admissible. 



The first action of PRO is . 





— 


putting forward /: ( 


/ 

V. 




CON attacks / with n: 




n 

/ 


( 


/ 


/ 


PRO defends this attack 




n 


with i: 




A— 


( 


f 


i 


CON attacks i with j: 




n j 


( 


f 


' \ 1 
% 


PRO defends i with i itself 
(so that i is self-defending) . 




n j 


CON is unable to put ^ 


' — 4 




forward other arguments ( 

that attack / or z so that ^ 


f 


• ) 



PRO closes S: 

This example shows that PRO must be allowed to repeat his arguments, while 
CON must be forbidden to repeat CON’s arguments (at least in the same ‘line 
of dispute’; see further below) 
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Example 5. (Odd loop failure). Suppose that PRO wants to show that m is 
admissible. 



The first action of PRO is 
putting forward m: 



C 



m 



CON attacks m with 1: 



m 



PRO defends this attack 
with p: 




CON attacks p with h: ; h 




PRO backtracks and 
removes p from S. He then 
tries to defend I with k 
instead: 




CON attacks k with m 
(and, as a bonus, 
introduces an inconsistency 
in S): 



I m 





k 



PRO has no other arguments in response to I and to, so that he is unable to 
close S into an admissible set. So to is not contained in an admissible set. Note 
that we cannot allow PRO to reply to to with I, since otherwise the set that 
PRO is constructing ‘around’ to is not conflict-free, hence not admissible. So 
we must forbid PRO to repeat CON’s moves. On the other hand, this example 
also shows that CON should be allowed to repeat PRO’s moves, since such a 
repetition reveals a conflict in PRO’s position. 



Example 6. (The need for backtracking). Consider next an argument system 
with five arguments a, 6, c, d and e and attack relations as shown in the graph. 
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This example shows that we must allow CON to backtrack. Suppose PRO starts 
with a, CON attacks a with d, and PRO defends a with e. If CON now attacks 
e with 6, PRO can defend e by repeating e itself. However, CON can backtrack 
to a, this time attacking it with c, after which PRO’s only move is defending a 
with b. Then CON can repeat PRO’s move e, revealing that PRO’s position is 
not conflict-free. 

Repetition Let us summarise our observations about repetition of moves. If 
PRO can defend an argument by using one of his previous arguments that is not 
backtracked, then should PRO do that? Further, does it make sense for PRO 
to repeat arguments advanced by CON? The same questions can be asked for 
repetitions by CON. 

i. It makes sense for PRO to repeat itself (if possible), because CON might 
fail to And or produce a new attacker against PRO’s repeated argument. 
If so, then PRO’s repetition closes a cycle of even length, of which PRO’s 
arguments are admissible. 

ii. CON should repeat PRO (if possible), because it would show that PRO’s 
collection of arguments is not conflict-free. 

iii. PRO should not repeat CON, because it would introduce a conflict into 
pro’s own collection of arguments. 

iv. It does not make sense if CON repeats itself, because PRO has already 
shown to have adequate defense for CON’s previous arguments. 

Finally, we show that CON should be allowed to repeat CON’s arguments 
when they are from different ‘lines’ of a dispute. A dispute line is a dispute 
where each move replies to the immediately preceding move; i.e., in a dispute 
line no backtracking is allowed. 

Example 7. (repetition from different lines) 



c 




d 



Suppose PRO starts a dispute for a and CON attacks a with b. Then PRO has 
two alternative ways to defend a, viz. with c and with d, but CON must be 
allowed to reply to each of them with e. 
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4 The Credulous Argument Game Defined 



We now turn to the formal definition of our argument games, starting with the 
credulous game. During a dispute a tree of dispute lines is constructed. This can 
be illustrated with the following format of disputes, taken from [29]. 

Example 2: Example 3: 

1. I PRO : a 1. I PRO : b 

2. II CON : ht 2. || CON : d 

3. Ill PRO: gt 

4. II CON : e 

5. ill PRO : ht 



Example 4: 



1 . 

2 . 

3. 

4. 

5. 



PRO : / 

I CON : n 
\ I PRO : i 
iil CON : j 
j j j I PRO : i (iv) 



Example 5: 

1. I PRO : m 

2. i| CON : I 

3. iil PRO : p 

4. iiil CON : ht 

5. iii PRO : k 

6. iiil CON : m (iii) 



The vertical bars “|||” indicate the level of the dispute, i.e., the depth of the 
tree. E.g., in Ex. 3, PRO responded to a response of CON (level 3), after which 
CON backtracks (level 2) to try a new argument against b. 

The “f” -symbol means that the player cannot respond to the last argument 
of the other player, while the -symbol means that the player is unable to 
respond to all arguments of the other player presented thus far. A number in 
the range (i-iv) means that a next move of the player would make no sense on 
the basis of the corresponding repetition guideline. 



Rules and Correspondence To establish a precise correspondence between 
disputes and preferred extensions, it is necessary to make the terminology more 
precise and to define the rules under which a dispute is conducted. 

- A move is simply an argument (if the first move) or else an argument attack- 
ing one of the previous arguments of the other player. 

- Both parties can backtrack. 

- An CO ipso (meaning: “you said it yourself”) is a move that uses a previous 
non-backtracked argument of the other player. 

- A block is a move that places the other player in a position in which he cannot 
move. 

- A two-party immediate response dispute (xpi-dispute) is a dispute in which 
both parties are allowed to repeat PRO, in which PRO is not allowed to 
repeat CON, and in which CON is allowed to repeat CON iff the second use 
is in a different line of the dispute. CON wins if he does an eo ipso or blocks 
PRO. Otherwise, PRO wins. 
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A main argument of a TPi-dispute is defended if the dispute is won by PRO. 

Proposition 1. (Soundness and completeness of the credulous game). An ar- 
gument is in some preferred extension iff it can he defended in every TPi-dispute. 



Proof. By definition of preferred extensions it suffices to show that an argument 
is admissible iff it can be defended in every dispute. 

First suppose that a can be defended in every dispute. This includes disputes 
in which CON has opposed optimally. Let us consider such a dispute. Let A be 
the arguments that PRO used to defend a. (in particular a G A.) If A is not 
conflict-free then Oi <— aj for some Ui, Uj G A, and CON would have done an eo 
ipso, which is not the case. If A is not admissible, then Ui *— b for some ai G A 
while b *-f A. In that case, CON would have used 6 as a winning argument, 
which is also not the case. Hence A is admissible. 

Conversely, suppose that a G A with A admissible. Now PRO can win every 
dispute by starting with a, and replying with arguments from A only. (PRO can 
do this, because all arguments in A are acceptable wrt A.) As long as PRO picks 
his arguments from A, CON cannot win by eo ipso, because A is conflict-free. 
So a can be defended in dispute. 

5 The Sceptical Argument Game Defined 

Above, PRO tries to show that the main argument is contained in a preferred 
set. This is known as credulous reasoning. If PRO wishes to verify whether 
the main argument is contained in all preferred sets, then PRO does sceptical 
reasoning. Before defining an argument game for this kind of reasoning, we must 
first explain why for sceptical reasoning it is relevant to study preferred semantics 
besides [9]’s grounded semantics, which is also meant for sceptical reasoning. 
The reason is that grounded semantics is too weak to capture certain types of 
sceptical conclusions. 

Example 8. (Floating arguments.) Consider the arguments a, b, c and d with the 
attack relations as shown in the picture. 




c 



^ d 



Since no argument is unattacked, the grounded extension is empty. However, 
this example has two preferred extensions, {a,d} and {b,d}, and both of them 
contain d. 
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Next we illustrate that there are cases where an argument system has a unique 
preferred extension but not all of its elements are contained in the grounded 
extension. 

Example 9. Consider four arguments a, b, c and d with the attack relations as 
shown in the picture. 



a 





d 



The unique preferred extension is {c}, so c is sceptically preferred, but the 
grounded extension is empty, since none of the arguments are unattacked. 

We now define the sceptical argument game. A result for sceptical reasoning 
can be obtained by observing that a dispute is symmetric, since CON also may 
be given the task to construct an admissible set, viz. for the attackers he uses. 
If CON succeeds, he has shown that there exists at least one admissible set not 
including the main argument. 

Proposition 2. (Soundness and completeness of the sceptical game). In argu- 
ment systems where each preferred extension is also stable, an argument is in all 
preferred extensions iff it can be defended in every TPi-dispute, and none of its 
attackers can be defended in every TPi-dispute. 



Proof. This result can be proven on the basis of the previous proposition, and 
by the fact that a stable extension attacks every argument outside it. 

Consider any argument system where all preferred extensions are stable. For 
the only-if-part of the equivalence, consider any argument a that is in all pre- 
ferred extensions. Then (by assumption that these extensions are also stable) 
all attackers of a are attacked by all such extensions, so by conflict-freeness of 
preferred extensions, none of these attackers is in any such extension. But then 
none of a’s attackers is credulously provable. 

For the if part. Let a be any argument that is credulously provable and such 
that none of a’s attackers are credulously provable. Then none of these attackers 
is in any preferred extension, so (by assumption that these extensions are also 
stable) they are attacked by all such extensions. But then a is defended by all 
these extensions, so they all contain a. 

The following example shows that this result does not hold in general. 
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Example 10 . Consider: 



d 




a 



a is contained in one preferred extension, viz. Ei = {a, c}, but not in the other 
preferred extension, which is E2 = {d}. Note that the self-attacking argument b 
prevents a from being a member of E2 although b is not itself a member. The 
problem is that E2 does not attack b so that a is not acceptable with respect to 
E2- This situation cannot arise when all preferred extensions are stable, since 
then they attack all arguments outside them. 



6 Discussion 

The present paper has provided simple and intuitive argument games for both 
credulous and sceptical reasoning in preferred semantics. However, there are still 
some limitations and drawbacks. 

A limitation is, of course, that the sceptical game is not sound and complete in 
general. A first drawback is the fact that the sceptical game actually consists of 
two parallel games, which is less elegant in applications in mediation and tutoring 
systems. In future research we hope to improve the games in both respects. 

Another drawback is that in some cases proofs are infinite. This is obvious 
when an argument has an infinite number of attackers, but even otherwise some 
proofs are infinite, as in the following example. 

Example 11 . (Infinite attack chain.) Consider an infinite chain of arguments 
tti, . . . , a„, . . . such that a\ is attacked by 02, 02 is attacked by 03, and so on. 



ai < fl2 < as < 04 < 05 <e 



PRO can win a game for ai (or for any other argument) since CON is never 
able to move a block, but PRO neither has a blocking move available. 

Nevertheless, it is easy to verify that with a finite set of arguments all proofs are 
finite. 
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Abstract. We extend our general approach to characterizing informa- 
tion to multi-agent systems. In particular, we provide a formal descrip- 
tion of an agent’s knowledge containing exactly the information conveyed 
by some (honest) formula </9. 

Only knowing is important for dynamic agent systems in two ways. First 
of all, one wants to compare different states of knowledge of an agent 
and, secondly, for agent o’s decisions, it may be relevant that (he knows 
that) agent b does not know more than (fi. 

There are three ways to study the question whether a formula (fi can 
be interpreted as minimal information. The first method is semantic and 
inspects ‘minimal’ models for (fi (with respect to some order < on states). 
The second one is syntactic and searches for stable expansions, minimal 
with respect to some language C* . The third method is a deductive test, 
known as the disjunction property. We present a condition under which 
the three methods are equivalent. 

Then, we show how to construct the order < by collecting ‘layered or- 
ders‘. We then focus on the multi-agent case and identify languages £* 
for several orders <, and show how they yield different notions of hon- 
esty for different multi-modal systems. Finally, some consequences of the 
different notions are discussed. 



Classification. Knowledge representation. Non-classical logics. 

1 Introduction 

What is a knowledge state? To answer this question, we give a general approach 
to characterizing information in a modal context. In particular, we want to obtain 
a formal description of an agent’s knowledge containing exactly, that is, at least 
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but not more than the information conveyed by some formula (p, in other words, 
the case in which tp is the agent’s only knowledge. Characterizing an agent’s 
exact knowledge state is important in dynamic agent systems in several ways. 
First of all, when the system evolves, one might wish to compare the different 
states of one agent: which actions (or, more specifically moves) optimally extend 
his knowledge? Secondly, in multi-agent systems, agent a may wish to be sure 
that all that b knows is tp, and exploit the fact that b does not know more 
than that. Finally, when such agents start to exchange information, they must 
be aware of principles governing their communication: Usually utterances are 
intended to convey minimal knowledge with respect to some domain (Grice’s 
maxim of quantity). 

Formulas ip representing all that the agent knows, are called honest. For the 
one-agent case, some observations about only knowing and honesty are well- 
accepted. For instance, where purely objective formulas are rendered honest, a 
typical example of a dishonest formula is (p = (Dp V Dg): if an agent claims 
to only know ip, he would know something that is stronger than p (i.e., either 
□p or Dg). A more sophisticated analysis of honesty generally depends on the 
epistemic background logic. What is especially important here, is which intro- 
spective capacities we are ready to attribute to the agent. For example, if the 
background logic contains the axiom of positive introspection Of; — > OOip we 
can infer DOp if only p is known. This seems innocent since the inferred knowl- 
edge is still related to the initial description p. On the other hand, if we accept 
the axiom of negative introspection n^Oip, then we can infer knowledge 

concerning q, for example D^Dg, from only knowing p. This knowledge cannot 
be derived from only knowing pAg, which intuitively represents more knowledge 
than only knowing p. As we stressed in [6], this kind of inferences effects the 
treatment of honesty for different modal systems. 

For the multi-agent case, intuition seems to be much less clear. Of course, 
where objective formulas are all honest in the one agent case, this property is 
easily convertible to formulas with no operator Dq, when considering honesty 
for agent a. Hence, a can honestly claim to only know D^p V Dfeg, for b ^ a. But 
if Da re-occurs in the scope of □&, the resulting formula D^pV becomes 

dishonest again if □{, represents knowledge. With mixed operators, in particular 
in the presence of negation, matters soon get fuzzy. 

Studies of ‘only knowing’ ([3,11]) and ‘all I know’ ([8]) have largely been re- 
stricted to particular modal systems, such as S5, S4 and K45. Recently Halpern 
[2] has also taken other modal systems such as K, T and KD45 into account. 
Although his approach suggests similar results for e.g. KD4, in [6] we adopted a 
more general perspective: given any modal system, how to characterize the min- 
imal informational content of modal formulas. For multi-agent only knowing, we 
only know of a (more or less) general approach by Halpern ([2]), putting a no- 
tion of ‘possibility’ to work on tree models, and, for the S5m case, enriching the 
language with modal operators Q\, for any formula f and agent i. 

In this paper, besides arbitrary normal multi-modal systems we prefer to 
use standard Kripke models, instead of Fagin and Vardi’s knowledge structures. 
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and Halpern’s tree models. We try to obtain this general view by putting our 
framework of [6] to work for the multi-agent case. In order to appreciate this 
fully, the reader has to realize that, in general, there are three ways to study the 
question whether a formula (p allows for a minimal interpretation (if allows 
for such a minimal interpretation, if) is called honest), and, if so, what can be 
said about the consequences of p under this interpretation. 

The first approach is a semantic one: Given a formula p, try to identify 
models for ip that carry the least information. This approach requires a suitable 
order < between states (i.e., model-world pairs) in order to identify minimal (or, 
rather, least) elements. For the simple (universal) S5-models the order coincides 
with the superset-relation between sets of worlds. Our challenge here is to give 
a general definition of such an order, which suits any multi-modal system. The 
second approach is mainly syntactic in nature and presupposes a sublanguage 
C* of ‘special’ formulas. Given a consistent formula p, we then try to find a 
maximally consistent set containing p with a smallest >C*-part. This approach 
can be identified as the search for so-called stable expansions, which are related to 
maximally consistent sets in a straightforward way. The last approach is purely 
deductive, and is also known as the disjunction property (DP): p allows for a 
minimal interpretation if for any disjunction in C* that can be derived from p, 
one disjunct is derivable from p. 

In [6] , we were able to formulate a condition under which the three approaches 
mentioned above are equivalent. This paves the way to focus on defining ‘suitable’ 
orders on information states in a general way, rather than trying to establish the 
equivalences of the characterizations for specific orders, again and again. The 
information orders on states that we consider are induced by layered orders <„ 
between states, where n settles the depth of the equivalence. 

For the one-agent case, we obtained minimality results with respect to the 
following languages (by considering appropriate orders on states): 

— C* = □£, where C is the full modal language {general honesty). However, it 
appears that under this choice, almost every formula is honest in the systems 
K, K4, KD and KD4. On the other hand, for many other systems there 
are no honest formulas. So for most systems, the notion of general honesty 
is trivial: all or no formulas are honest. 

— C* = , where is the modal language where no □ occurs in the scope 

of a negation {positive honesty). For S5, the corresponding notion of honesty 
coincides with the approach in [3]. Moreover, for all systems except K, KD, 
K4 and KD4, this notion of honesty is not trivial. 

For the multi-agent case, there are many more options. Generalizing the 
first language above gives rise to a notion of honesty which encounters, mutatis 
mutandis, the same problem of trivialization as states for the one agent case. The 
second, so-called positive language can be generalized in different ways, which 
for most systems lead to nontrivial notions of honesty. The anomalous cases are 
still the weak doxastic logies (generalizing an observation of Halpern in [2]): in 
KDm and KD4m all formulas p for which is consistent, are honest; in 
and K4m, even all formulas are honest. This means that in KD4m, for example. 
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agent a can honestly claim that he only knows whether he knows p, which we 
believe to be counter-intuitive. 

In this paper, we present three generalizations of positive honesty: one corre- 
sponds to the ‘a-objective’ language (the formulas do not contain Da), one to the 
‘a-positive’ language (no Da in the scope of negation), and one that combines 
these two. 



2 Modal Logical Preliminaries 

Let us agree on some technicalities. Our multi-modal language £ or £-^ has 
finitely many modal operators Di, O 2 , . . . , over a finite set of atoms V = 
{p, q,r . . .}, using the classical connectives A and V. Here {1,2,..., m} encodes 
the set of agents A. We use a for an arbitrary agent in A on which we focus. 
The operator Da denotes “Agent a has the information that ...”, which may 
involve knowledge, belief or any other propositional attitudes. The dual modal 
operators Oi, O 2 , . . . , are introduced by definition: OaP = Given a 

set of formulas T, we define a’s knowledge about F by DaT = \ p G F} 

and a’s knowledge in F by = {p \ G T}. 

A measure of modal complexity of formulas, called modal depth, has the usual 
recursive definition: d{p) = 0 (for p G V), d{—~ip) = d{(p), d{ip A'lp) = d{ip V ^/>) = 
max{(i((p), d(i/')} and d{Uip) = d{ip) + 1. We often consider the sublanguage of 
formulas of limited modal depth: = |(p G £ | d{ip) < n}. So, £(o) is the 

purely propositional subset of £ (void of modal operators) . Other sublanguages 
of interest will be defined in the sequel. 

We use multi-modal Kripke models {W, i?i, . . . , Rm, V) or {W, R, V) to in- 
terpret £; here wRaV or v G i?a[w] means that given world w, world v is an 
epistemic alternative to a. Truth is relative to a model- world pair (‘state’, for 
short). The connectives A and V are interpreted as usual; the modal operators 
also get the classical interpretation: M,w \= iff for all v G Ra[w\ : M ,v \= p. 
The theory of a state {M,w) is Th{M,w) = {ip \ M,w ^ ip}. If the model is 
obvious from the context, we will omit it and simply write w \= p. Consequence 
is defined relative to a given set of models S : F ^5 p iff M, w \= p for all 
M G S s.t. M,w \= F. States are assumed to be related by what we call an 
information order <“ for any agent a; for the time being <“ is only required to 
be a pre-order (i.e. reflexive and transitive). A major question is which formulas 
are preserved moving from w to w' if w <“ w' . It will prove important to single 
out so-called persistent sublanguages of such formulas, in particular those that 
are rich enough to reversely characterize the information order. 

The inference relation h is obtained relative to a modal system S, which 
at least contains classical propositional logic and the rule defining the minimal 
system K.: F \- p ^ ^aF L Fi^^p. Formulas p and ip are equivalent in S, if both 
p \~s and if) hs P- The logics S that we consider have the nice property that 
£(„) is finitary: since V is finite, S induces only finitely many equivalence classes. 
A set F is S-consistent if for some p: F P', F is maximal S-consistent (S-m.c.) 
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if S-consistent, though it cannot properly be extended to a larger S-consistent 
set. A formula is a theorem of S if 0 hs (fi, also written as hs (fi- 

Here are some familiar axioms and their corresponding condition on the 
accessibility relation: T ^ ip {reflexivity); D \^aP ^aP (seriality); 4 
\P\aP ^a^aP {transitivity)] 5 <>aP — *■ ^a^aP {Euclidicity)] B (p ^ 
{symmetry); G <>a'iitiaP ^a^aP {confluence). 

Axiom 4 is also known as “positive introspection” ; axiom 5 in its equivalent 
form -^tP^aP ^a~^^aP is known as “negative introspection” . Unimodal systems 
(involving only one agent’s modality) are characterized by their constituting rules 
and axioms: K, KD, KD4, KD45, etc. If S is a standard modal system, then 
Sm is its TO-agent counterpart. A state verifies a logic S if it verifies all the 
theorems of S. 

3 Minimal Information in Multi-modal Logic 

Suppose we have an information order <“ on states. When do we consider the 
information p to be minimal for agent a? We suggest that p constitutes minimal 
information for a, or that p is a-honest, if ^aP is true in a least state {M,w). 

Definition 1. A formula p is a-honest with respect to S and <“ ijf there is an 
S-state {M,w) such that M,w |= ^aP and 

Mfw' 1= ^aP =k M,w <“ Mfw' for all S-states {M',w'). 

This characterization of minimal information may however not always be conve- 
nient. In some cases one would prefer a syntactic characterization, a deductive 
test, or a combination of these. This can be achieved by relating the informa- 
tion order <“ to a proper sublanguage £“ through persistence [for all p G : 
M,w <“ M',w' =k {M,w \= p ^ M',w' 1= p)] and a converse of this, called 
characterization [for all p G L°‘{M, w \= p ^ M' , w' \= p) =k M,w <°- M' , w']. 
We are now able to propose alternative approaches to minimality: 

(1) Formula p has a <“-least verifying S-state (i.e. there exists a state {M,w) 
verifying S such that M,w [= Og_p and for all states {M',w') verifying S: 
M', w' h ^aP M,w<^ M', w'). 

(2) Formula p has an £“-smallest S-m.c. expansion (i.e. there exists a maximal 

S-consistent T such that p G F and for all S-m.c. A: S A Tn£“ C A). 

(3) Formula p has S-DP with respect to i.e. p is S-consistent and for every 
V:!, V’ 2 , • ■ • V’fe G hs (V’l V • • • V ■0fc) ^ for some i < fc : (p hs V’i- 

Theorem 1. Let £“ he a characteristic persistent sublanguage of C with respect 
to <“. Then the minimal information equivalences hold for £“ and <“, i.e., 
the conditions (1), (2) and (3) above are equivalent. More specifically, given 
the condition, p is a-honest with respect to <“ and S ijf (all statements are 
equivalent) : 

— G\aP has a <'^-least S-state 

— G\aP has an -smallest S-m.c. expansion 
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— Lp has a smallest a-stable expansion 

— has S-DP over 

Here, S is a-stable \i S = for some S-m.c. P, and 27 is a stable expansion 
of 1/7 if ^ is stable and i/7 G 27. Linking some of these criteria, we can say that 
p is (a-)honest if true in some world (w) in an appropriate model (M) where 
part of the knowledge in that world is minimal (since then □^Th(M, w) is its 
□ ~£“-smallest stable expansion), which seems a fairly intuitive notion. When 
the equivalent notions of Theorem 1 hold for a particular order <“, system S 
and language we say that <“ and £“ determine a notion of honesty in S. We 
can also link up the semantic definition of honesty with deduction, providing a 
perhaps even more intuitive characterization:^ 

Corollary 1. Let he persistent and characterizing for <°“ . Then p is a-honest 
with respect to <“ and S iff there is an S-state (M,w) such that: 

— M, w 1= PiaP <ind Vi/7 G £“ : M, w \= if ^ P^aP bs if 

— or, equivalently, \/if G £“ : M, w \= if PaP bs if 

All this makes clear that we ‘just’ have to specify which part of the knowledge 
is involved. More formally speaking, we have to pinpoint the right information 
order <“, or, equivalently, its characterizing persistent sublanguage This, 
however, is a non-trivial problem, since surely not every information order has 
such a characterizing persistent sublanguage. For example, if <“ is mere iden- 
tity or even isomorphism of models, not even the entire language suffices to 
characterize the model (up to isomorphism). Also, pursuing our results for the 
single-agent approach, we know that unlimited bisimulation is too strong a re- 
quirement, vide [6]. As we showed in our earlier paper, a layered, limited kind 
of bisimulation is preferable. Two technically correct orders in the single agent 
case will be generalized in the next subsections. Although the initial, so-called 
general information order is not intuitively sound, it serves as a first step to more 
profound information orders. But we start by generalizing an umbrella result for 
such layered pre-orders. 

3.1 Layered Information Orders 

An information order and its characterizing persistent language can be obtained 
along fairly general patterns from the underlying layered orders and their char- 
acterizing persistent languages. This is a very convenient tool for many orders 
to follow, since we can restrict attention to one simple layer at the time. 

Suppose <“ is a pre-order on the set of model-world pairs for each natu- 
ral number n (‘layer n’). From now on, assuming M = {W,R,V) and M' = 
(IF', R' , V), the base case will be defined as M, w <g M', w' 4PV (w) = V'{w'). 
Then we define <“ for any layered order <“ by: 

M,w <“ M' ,w' Vn G IN Vu'Gi?(j[w'] 3v€Ra[w] : M, u <“ M' ,v' . 

^ This characterization was triggered by a question of Amis Vilks. 
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We say that <“ is induced by <“ if the above equivalence holds. Finally, let £“ 
be a sublanguage and = £“ n £(„) be its subset of formulas of modal depth 
up to n. The following Lemma explains how a persistence and characterization 
result for languages with finite depth and layered orders can be lifted to the full 
language and the induced order. Lemma 1 will be implicitly used throughout 
the paper. 

Lemma 1 (Collecting). // is persistent and characterizing for <“, and 
is closed under V, then is persistent and characterizing for <“. 

We will now inspect orders inspired by Ehrenfeucht-Fra'isse games (see, for ex- 
ample, [1,4]). 

3.2 The Multi-modal General Information Order 

In the first Ehrenfeucht-Fra'isse order the underlying, layered order is in fact 
an equivalence relation (“EF-equi valence”). Define recursively (recall that 
M, w ~o M', w' V (w) = V'(w')) ^ by: M, w ~n-i-i M' , w' iff 

— M, w ~n M' , w' & 

— 'ii£A'iv'€R^[w'] '■ M,v c:Zn M',v' (back) & 

— 'ii£A'iv£Ri[w]3v'£R'^[w'] :M,v~n M',v' (forth) 

Then the general information order is induced by By a rather straight- 
forward induction, one shows that is characteristic and persistent for 
and hence the collecting lemma gives that Dalf is persistent and characterizing 
with respect to C“. So, the information equivalences hold for and Dalf. We 
say that ip is generally a-honest if has a C“-least model. This implies the 
usual equivalences, i.e., and DaT determine a notion of a-honesty in S, for 
any modal system S. 

However, as we noticed in [6], this notion of honesty is, though technically 
correct, intuitively a rather poor one. It also leads to excessive trivialization. In 
weak doxastic logics such as KD^ and KD4m, all formulae p> such that is 
consistent, are generally a-honest. For and K4m, we can go a step further: 
all formulas are honest, as Halpern [2] notices for the first system. 

In (relatively) strong logics, however, i.e. systems with some form of negative 
introspection (such as 5, B and G), there are virtually no honest formulas. 
Because then there surely are non-theorems such that h ^aPi V ^aP 2 

which leads to an easy violation of the Disjunction Property. For example, p is 
generally a-dishonest in S5r„: note that the formula Dg_Og^ni(,p is an 

instantiation of 4, so this formula is derivable from in S5m) whereas neither 
of its disjuncts is. 

So, as in the unimodal case, not much is left. Among the epistemic logics 
only a few systems such as Tm and S4m survive. But even then has coun- 
terintuitive effects: growth of information does not lead to less uncertainty, as it 
should be. 

^ The superscript A is omitted whenever clear from context. 
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4 Generalizations of the Positive Order 

From the single agent case we know that only the positive information order 
is intuitively sound with respect to honesty. In a positive information order we 
merely want to preserve positive knowledge of one or more agents. In other 
words, we disregard negative knowledge, i.e. knowledge of not knowing. We, 
typically, encounter back simulation on the underlying layers, but usually no 
forth simulation, or only a restricted form of forth simulation. 

It is not a priori clear which notion of positive information order is involved. 
We will discuss several options in what follows, of which the last is the more 
general one, using both underlying layers from the general and from the so-called 
‘objective’ information order. We start by discussing a rather straightforward 
generalization from the single agent case. 

4.1 Positive Honesty 

The positive information order only preserves positive knowledge of agent of a. 
It is the most obvious generalization of one-agent positive honesty. The formulas 
of the characterizing language do not have negative occurrences of Da, and so, 
by definition, no <>a as well. Formally, let consist of those (p & C for which <p 
does not contain Da in the scope of Formulas in £+“ are called a-positive.^ So, 
V and n^pA^q are members of £+“, but and OapA' Dhg 

are not. 

Now consider £“ = This is a correct generalization of the single agent 

positive language, which by itself is a generalization of the so-called objective 
one-agent formulas which suit S5. We will call the elements of a-positive 

knowledge formulas. What is the corresponding <“? Essentially, the underlying 
order displays the back direction of the EF-equi valence for all agents, operating 
on o-positive formulas until subformulas are reached that are Da-free, where full 
EF-equivalence for all agents except a takes over. Then, M,w <nfi M',w' iff: 

- M,w M',w' t 

— Vi G AWv' GR'^[w'] : M,v <+“ M',v' (back) 

Let the positive information order <“*■“ be induced by Then is charac- 
teristic and persistent for so the collecting lemma guarantees that is 

persistent and characterizing with respect to <■*"“. Thus, we obtain the following. 

Theorem 2. The minimal information equivalences hold for <“*■“ and □aT“''“. 

Now, (fi is called positively a-honest if DaP has a <“*'“-least model. 

Thus, we have that <“*■“ and determine a notion of a-honesty in 

S, for any system S. So, the notion of positive honesty is technically sound, 
that is, there is a persistent language that characterizes the positive information 
order, and it seems a proper extension of the unimodal case. It avoids problems 

BNF-definitions of the languages considered are given at the end of this paper. 
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objective honesty encounters, such as one noticed by Halpern [2] for 85^ (or, 
more precisely, extensions of KB4m): suppose p is some fact totally unrelated to 
a formula ip (for example, p may not occur in ip), then \^aP b ^aP^^a^b^^b^aP- 
It is clear, however, that each of the disjuncts itself does not follow from 
Yet p may constitute innocent knowledge, e.g. □{,( 7 . But for our notion of positive 
honesty, this counter-example to the DP test is avoided by the restriction that 
the disjuncts should be in the a-positive knowledge language; here, obviously. 

Yet we do not want to exclude other possible notions of honesty a priori, and 
therefore now turn to one studied earlier. 

4.2 Objective Honesty 

To make a different start in formalizing multi-agent positive honesty, we return 
to Halpern’s [2] definition of a-objective formulas and the notion of honesty con- 
nected to it. Halpern reserves the notion objective honesty for the two strong 
doxastic systems K45m and KD45m- This seems harmless for these two sys- 
tems. Our main concern is that developing a whole apparatus for just two modal 
systems, and again different ones for others, leads to an approach which lacks 
generality and in fact conceals much of the general pattern. In fact, in Halpern’s 
approach it is not clear why a-objective formulas might be suitable for the two 
systems mentioned. We think that we can in fact explain much of the reasons 
for its feasibility. 

The idea of a-objective knowledge is that agent a only has knowledge of 
information ‘outside’ of a, i.e. knowledge of facts and other agents’ knowledge. 
Such other agents’ knowledge may again involve a’s knowledge, but still counts 
as external for a. This is easily formalized when we start with the a-objective 
(that is, wide scope a-operator-free) formulas: let consist of those p & C 
for which p does not contain wide scope Da. In other words, in an a-objective 
formula, every Da and Oa has to be in the scope of a or Ob (6 yf a). Examples: 
□aP V Obq, are not in but ^Dfep and Ob{p V are. 

So where does the agent a’s knowledge enter the story? Here she is: consider 
A formula is then called an a-objective knowledge formula if it is 
of the form with p € 

The corresponding Ehrenfeucht-Frai'sse order <“ can be obtained from the 
underlying layered order, which is again an equivalence relation. The recursive 
clause for is the following: M,w M',w' iff 

- M',w' & 

~ Vz yf div' &R[[w'\ 3vGRi[w] : M,v M',v' (back) & 

— Vz yf adv € Ri [z«] 3v' G i?' [zc'j : M, v M' , v' (forth) 

So, not only uses the general EF-equi valence relation on layer n, its overall 

formulation is close to that of the general information order, be it that it shares 
the exclusion of agent a with the positive information order. 

One can now prove that is characteristic and persistent for — Thus, if 
we define objective information order to be induced by — the collecting 
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lemma guarantees that “ is persistent and characterizing with respect to 

Theorem 3. The information equivalences hold for and . 

This again implies that and Da/l”® determine a notion of (objective) a- 
honesty in S, for any system S. 

As can been seen from the format of the a-objective formulas, agent a’s 
knowledge is not taken into account. For fully introspective this is unproblematic 
in the one-agent case: there one can show that positive knowledge formulas can 
be reduced to disjunctions of objective knowledge formulas, which implies that 
for each system containing K45, objective honesty amounts to positive honesty. 

It should be emphasized that this equivalence only holds for the one agent 
case and full introspective knowledge. For more agents there is no such reduction, 
since an objective knowledge formula need not be (equivalent to) a positive one, 
e.g. is an a-objective knowledge formula which is not related to any a- 

positive knowledge formula whatsoever. If we want to generalize this equivalence 
to fully introspective multi-agent systems, we have to relax the notion of positive 
formula somewhat, as will be done in the next subsection. 



4.3 Positive-Objective Honesty 

We want to generalize objective knowledge to what we consider to be a more 
adequate notion of multi-modal honesty. The a-positive- objective formulas can, 
roughly, be characterized as having no wide scope negative occurrence of Da 
operators. Again assume for simplicity’s sake that we only consider formulas 
where every Oi is replaced by Let consist of those p £ L for which 

every Da in q? in the scope of ^ is also in the scope of a with i ^ a. Thus, 

£±a 

can also be regarded as the closure of £ “ under the operations A, V and 
□a. Examples: DapV Dfeg, DapA and U^Ui^^UaP are members of but 
and V Dfeg are not. 

Once again, what is the corresponding <“? For evaluating formulas, we es- 
sentially want to have recursive back moves for agent a in the EF-order, until 
a-objective formulas are reached, and then proceed with the a-objective equiv- 
alence. So, more formally, the recursive step in is defined by M,w 
M',w' iff: 

— M,w — M',w' & 

— yv'GR'J[w'] 3vGRa[w] : M,v M',v' {hack) 

Then the a-positive-objective information order <^“ is induced by <j^“. 

Now consider £“ = Notice that £*“ extends both £+“ and 

thus generalizes both the positive and the objective approach. Since is 
characteristic and persistent for <j^“, the collecting lemma shows that 
is persistent and characterizing for <^“. Now p is called positive- objectively a- 
honest when DaP has a <^“-least model. 
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Theorem 4. The minimal information equivalences hold for <=*=“ 

This implies that and determine a notion of a-honesty in S. We 

can show that for fully introspective systems the extension from objective to 
positive-objective formulas is immaterial, since then again a’s positive-objective 
knowledge can be reduced to a-objective knowledge. So, objective honesty and 
positive-objective honesty coincide for K45m and KD45m, and S5m- Although 
positive, objective, and positive-objective honesty agree on (one agent) S5, they, 
surprisingly, do not on S5m (rn > 1). Since DaP V is derivable in 

S5m, there are virtually no (positive-)objectively honest formulas in this system. 
However, we have already seen that for S5m, the positive information order 
seems correct. 

5 Relating and Evaluating Types of Honesty 

In the previous section we noticed that for fully introspective systems the differ- 
ent types of honesty may actually coincide, depending on the number of agents 
TO. But before checking examples and assessing the intuitive correctness of these 
notions, some more general observations can be made. 

The types of honesty distinguished in this paper are ordered as indicated in 
Figure 1. This hierarchy easily follows from DP, using the fact that U 

C n,£±“ C □,£. 



general honesty 

T 

positive-objective honesty 




positive honesty objective honesty 



Fig. 1. Relating notions of honesty 



This reduces the number of checks to be made for specific examples. In gen- 
eral, dishonesty can be shown fairly easily by using the relevant DP, but it may 
be harder to show honesty more or less directly. It is not prima facie clear how 
to prove honesty, since DP then has to be checked for an infinite set of formulas. 
Also, minimality of stable expansions encounters similar problems and finding 
the least model may be non-trivial, which is related to the complexity of the 
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information orders. Presumably, for many relevant multi-modal systems these 
intricate orders have simple counterparts. 

To assess the adequacy of the notions of honesty, we picked a number of 
examples and checked their (dis)honesty for the four types proposed, and for the 
modal systems S4m, K45m, S5m (m > 1). In addition to hierarchy constraints 
and the observation about collapse, we already noticed that there are hardly any 
generally honest formulas for K45m and S5m- 

For the former system also inconsistent formulas are vacuously generally a- 
honest. Neither full information nor inconsistent information is of much interest 
here. Moreover, for S5m we also noticed large (positive-)objective dishonesty. 
Therefore, the in some sense maximally honest formulas (characterizing inno- 
cent partial knowledge) display the left-hand pattern in Table 1 (‘pob’ denotes 
positive objective honesty, etc.). This pattern manifests itself in many formulas 
that are also intuitively honest for agent a: p, .... The most challenging 
cases are disjunctions of (negated) knowledge formulas. As we will see, whether 
or not they are intuitively honest largely depends on the agency of the knowing 
subject. So, also the following formulas are indeed maximally a-honest: DbpVnbg, 
□apVOaf?, OhpVOaQ, □fcpVOfeg, andpVg. The other extreme are the totally dis- 
honest formulas displaying the pattern on the right, exemplified by the paradigm 
□aP V Dag. 



Table 1. Patterns of maximal (left) and minimal (right) honesty 





S4m 


K45m 


S5m 




S4m K45m S5m 


gen 


-f 
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- 


gen 
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pob 


-f 
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pob 


- 


obj 


+ 


-f 


- 


obj 


- 


pos 


-f 


-f 


+ 


pos 


- 



There are many (34) intermediate cases. A very common pattern here is the 
one in which honesty only depends on the amount of introspection attributed 
to the agents, witnessed by the pattern on the left below. Examples of formulas 
with this honesty pattern (displayed in Table 2, left) are DapV Dfeg, DapV ObQ, 
and Dg^pWq. Also, honesty may depend on the type and not on the modal systems 
under inspection, as with the formula DaP V showing the pattern on 

the right in Table 2. 

Finally, two more complicated patterns can be obtained by the formulas 
□apV (ou the left) and DaP V □aOaDa? (right) in Table 3. 

The tentative conclusion from inspecting these examples is that positive hon- 
esty seems to be the intuitively correct notion for multi-modal systems. 
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Table 2. Introspection (left) and type (right) dependent honesty patterns 
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Table 


1 3. Some other patterns of honesty 
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6 Conclusion 

We have given generalizations of information orders for multi-agent only know- 
ing, which apply to arbitrary modal systems and ordinary Kripke models. Using 
a general theorem relating information orders and their corresponding (sub-) 
languages, we were able to identify several equivalent characterizations of hon- 
esty. In particular, we have explored the general information order and some 
positive and objective information orders. So-called positive honesty seems the 
intuitively correct notion here. 

An interesting question for future research concerns the transfer of techniques 
developed for the single agent case to multi-modal systems. For example, one 
might try to adapt the amalgamation techniques as used in [6] to prove, by 
means of the disjunction property, honesty in S4 and weaker systems. It is also 
interesting to generalize the test procedure as proposed and proved correct in 
[2] for objective honesty to other types of honesty. 

There are many ways to extend the multi-agent perspective on only knowing. 
For instance, one might give up the assumption that all agents use the same 
logic and move to heterogeneous systems. Also, a notion of group honesty is 
as yet unexplored. Finally, we like to investigate multi-agent honesty from a 
more constructive perspective: can we give a procedure to generate a minimal 
model for a given formula? And, can we extend the partial approach of [5] to 
the multi-agent case? 
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Appendix: Defining Langnages 

Here we give explicit BNF definitions of the (sub)languages considered in this 
paper. Before doing that we summarize the languages in Table 4: 



Table 4. Symbols, names and informal descriptions of languages 



Name 



Language 
full, general 
a-objective 
a-positive 

a-positive-objective 



Condition 
no restriction 
only Da in scope 
no Da in scope of ^ 

□ a only in scope -i if in scope 



The languages are now defined by the following BNF expressions: 



Table 5. Languages and their BNFs 



Name 


BNF definition 
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Abstract. In this paper, we present a logical framework that combines modality 
with a first-order quantification mechanism. The logic differs from standard first- 
order modal logics in that quantification is not performed inside the states of a 
model, but the states in the model themselves constitute the domain of quantifi- 
cation. The locality principle of modal logic is preserved via the requirement that 
in each state, the domain of quantification is restricted to a subset of the entire set 
of states in the model. We show that the language is semantically characterised 
by a generalisation of classical bisimulation, called history-based bisimulation, 
consider its decidability and study the application of the logic to describe and 
reason about the topologies of multi-agent systems. 



1 Introduction 

Over the last years an increasing interest can be observed in large-scale distributed com- 
puting systems that consist of heterogeneous populations of interacting entities. Exam- 
ples from practice include for instance the electronic market places in which buyers and 
sellers come together to trade goods. This trend can also be observed in the fields of 
computer science and artificial intelligence with the current focus on multi-agent sys- 
tems [14]. In these systems, an agent constitutes an autonomous entity that is capable 
of perceiving and acting in its environment and additionally has a social ability to com- 
municate with other agents in the system. In heterogeneous multi-agent systems, the 
agents are assumed to he of different plumage, each having their individual expertise 
and capabilities. Moreover, in open multi-agent systems, new agents can be dynami- 
cally integrated [5]. 

One of the issues in open heterogeneous multi-agent systems is the agent location 
problem, which denotes the difficulty of finding agents in large populations [13]. For 
instance, given an agent that needs to accomplish a particular task that it is incapable of 
performing all by itself, the problem amounts to finding an agent that has the expertise 
and capabilities to join in this task. In these systems, it is typically impossible for the 
individual agents to maintain a complete list of the agents that are present. That is, each 
of the agents has a list of other agents that it knows of, but due to the dynamics of 
the system this list is normally not exhaustive. Hence, the agent needs to communicate 
with the other agents in the system in order to come to know about new agents that it is 
currently not aware of to exist. This enables the agent to extend its individual circle of 
acquaintances. 
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The purpose of this paper is to develop a formal logic to describe and reason about 
network topologies, like for instance the topology of multi-agent systems. Formally, 
such a network topology can be represented by a directed graph where the nodes in the 
graph denote the entities in the system and the edges make up the acquaintance relation, 
describing what entitites know each other. Seen from a logical point of view, these 
graphs constitute Kripke frames, which are employed in the semantics of modal logic 
[11]. This observation naturally leads to an approach of describing network topologies 
by means of modal logic, which is corroborated by the fact that we want to describe and 
reason about network topologies with respect to a local perspective, that is, from the 
viewpoint of a particular entity in the topology. Basic modal logic however is not fit to 
describe and reason about network topologies, as it does not have the expressive power 
to distinguish between bisimilar structures, like for instance loops and their unfoldings, 
which clearly induce different network topologies. 

In this paper, we present an extension of the basic modal logic with variables and 
a first-order quantification that complies with the locality principle of modal logic. It 
differs from the standard first-order modal logics [6] in that there is no quantification 
inside the states of a model. Instead, the states in the model themselves constitute the 
domain of quantification; i.e., the logic covers a mechanism of binding variables to 
states in a model. Such variable binding mechanisms are also gaining attention in the 
field of hybrid languages, which are languages originally developed with the objective 
to increase the expressiveness of tense logics [4]. Our framework can be viewed upon 
as a formalisation of hybrid languages in terms of an equational theory in which we 
can reason about the equalities (and inequalities) of states of a model. We preserve the 
locality principle of modal logic via the requirement that in each state the domain of 
quantification is restricted to a subset of the entire set of states in the model. 

Moreover, we define a semantic characterisation of the logic, which is based on a 
generalisation of the classical notion of bisimulation equivalence. Instead of relating 
states, this generalised type of bisimulation relates tuples that are comprised of a state 
together with a sequence of states. In the semantic characterisation, these additional 
sequences are employed to represent variable bindings that are generated during the 
evaluation of formulae. 

The remainder of this paper is organised as follows. In Section 2, we start with con- 
sidering basic modal logic and graded modal logic, and argue that these are not well-fit 
as logics for network topologies. In Section 3, we develop the syntax and semantics of a 
general modal logic with an implicit bounded quantification mechanism. Subsequently, 
in Section 4, we establish a semantic characterisation of the logic, while the decidability 
of the logic is discussed in Section 5. Additionally, in Section 6 we consider the appli- 
cation of the logic to describe and reason about the topologies of multi-agent systems. 
Finally, we wrap up in Section 7 where we provide some directions for future research. 



2 Towards a Logic for Network Topologies 



The most straightforward logic to describe and reason about network topologies is stan- 
dard first-order logic. However, rather than taking the bird’s-eye perspective, our aim is 
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to reason about network topologies from a local point of view. The following example 
explains the difference between these two perspectives. 

Example 1 {Local point of view) 

Consider an agent w that knows two agents vi and V 2 , which each in turn, know one 
other agent. The structures M. and JV in Figure 1 constitute two of the possible situ- 
ations. In situation A4, the two acquaintances of the acquaintances of w are distinct, 



Vi 




w • 




u 



V2 



M 



Fig. 1. Network topologies with indirect acquaintances 



while in N these two acquaintances are one and the same agent. From an external point 
of view these two structures are clearly distinct. However, what if we consider them 
from the local perspective of wl The crucial observation here is that whereas v\ and V 2 
are among the agents that are known by w, the agents ui and U 2 are not. Consequently, 
as w does not know the identity of either ui and U 2 , it cannot decide whether they 
are the same or distinct. In other words, as far as w is concerned, the actual situation 
could be the one depicted by M. as well as the one depicted by N. However, standard 
first-order logic can obviously distinguish between these two situations. 

Our purpose is to develop a (fragment of first-order) logic that is fit to reason about 
network topologies from a local perspective. 



2.1 Basic Modal Logic 

Languages that are designed to describe and reason about relational structures from a 
local perspective, are the languages of modal logic. The basic modal language can be 
defined as follows. 

Definition 2 (Basic modal language Cq) 

Formulae ip in the language Cq are generated using the following BNF-grammar: 

ip \:=T I Pi Ap2 I ~^P I <>P- 

A modal formula is either equal to T, the conjunction of two modal formulae, the 
negation of a modal formula, or the operator () followed by a modal formula. It is the 
operator 0 that gives the language the modal flavour; it has various readings like for 
instance the interpretation of expressing possibility. The dual □ of this operator, which 
is defined as ^0^, can be thought of denoting necessity. Finally, we assume the usual 
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abbreviations _L for ^T, ip\ V ipi for A ^<^ 2 ) and ip 2 for ^ipi V (p 2 - Note 

that we do not consider propositional variables here. 

The basic modal logic is used to reason about relational structures, especially about 
relational structures that are referred to as Kripke structures. 

Definition 3 {Kripke structures) 

A structure for the language Cq, which is also called a Kripke structure, is a tuple of the 
form: 



where W constitutes the domain of the structure, which elements are referred to as 
states, nodes, worlds or agents, and r C Vk x kk denotes an accessibility relation on W. 
For each state w G W ws use the notation r{w) to denote the set {u GW \ r{w, u)}. 

The interpretation of modal formulae is given in the following truth definition. 

Definition 4 {Truth definition for Cq) 

Given a structure Ai = (VF,r), a state w G W and a formula ip G Cq, the truth 
definition A4 , u> |= is given by: 



Additionally, we have AA\= p if for aliw G W it holds that A4,w \= p. 

Kripke structures can be viewed upon as representing network topologies: the elements 
of W constitute the nodes in the network and the relation r defines the accessibility 
relation; e.g., r{w, u) denotes that w has access to u, or that u is an acquaintance of w, 
or that w knows u, or that w can communicate to u, and so on. The modal logic can 
then be used to describe these topologies. For instance, the formula ()()T expresses that 
there exists an acquaintance of an acquaintance. That is, Ak, w \= ()()T holds in case 
there exist v and u such that r{w,v) and r{v,u). The basic language £q is however 
not rich enough for adequate descriptions of network topologies. Consider for instance 
the two structures A4 and Af in Figure 2. In the structure A4, there is an agent that 



M = {W, r), 



M,w h T 

M,w 1= A (/?2 ^ AI, w\= p\ and Al, u> \= p 2 

Ai,w\=^p ■^M.,w\^p 

Al, w 1= ()p G r{w) : Al, v \= p 



M 



w 




V • 



Af 



Fig. 2. Different number of direct acquaintances 



knows two different agents, while in the structure Af only one agent is known. From 
the perspectives of w and v these two structures clearly denote distinct situations, as we 
assume that agents know the identities of their acquaintances and hence, can distinguish 
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between the situation that their circle of acquaintances is comprised of two agents from 
the situation that this circle consists of only one agent. However, the basic language 
lacks the expressive power to distinguish between both networks; i.e., there does not 
exist a formula (/? G £q with M.,w \= ip and N , v ip. Formally, this follows from the 

fact that these structures are bisimilar. 



2.2 Graded Modal Logic 

Graded modal logic is an extension of the basic modal language that deals with numbers 
of successors [10]. Rather than one modal operator 0 the graded language contains 
a set {Ora I n > 0} of operators. A formula of the form 0n£ expresses that there 
exist more than n accessible worlds in which p holds. Hence, graded modal logic can 
distinguish between the above models Af and M. For instance, we have M,w |= OiT 
but A/", V OiT. 

Graded modal languages are still not suitable to describe network topologies. For 
instance, consider the two structures M. and M in Figure 3, which denote a loop and 
its unfolding, respectively. In M., there is an agent that knows only itself, whereas in 




Fig. 3. Loop and its unfolding 



M there is an agent that knows another agent that knows another agent that knows yet 
another agent . . . and so on. However, whereas we believe that an adequate logic for 
network topology should be able to distinguish between these two structures, it can be 
shown that graded modal logic does not possess the expressive power. 



3 Modal Logic with Bounded Quantification 

Our analysis of the reason why basic modal logic and its extension with graded modal- 
ities are not adequate to describe network topologies, is that they lack a mechanism of 
dealing with identities. For instance, if we reconsider the structure At from Figure 2, 
then although v\ and V 2 have no distinguishable property that is expressible in the lan- 
guage Cq, there is one significant intrinsic difference between them and that is their 
identity; i.e., they are two distinct states in the topology. 

Our approach in developing a logic for network topologies therefore consists in 
extending the basic modal logic with a mechanism of dealing with state identity. That 
is, the language Cq is expanded with a collection Var of variables that are used as state 
identifiers. In order to be able to instantiate these variables we additionally introduce a 
form of implicit bounded quantification. We refer to this language as C\. 
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Definition 5 {The extended modal language C\) 

Given a set Var of variables, terms t and formulae Lp are generated using the following 
BNF-grammar: 

t ::= self \ x 

(fi ::= (ti = 12) I tpi A (p 2 I I I 

where x ranges over the variables of Var. 

We assume the usual abbreviation Vx<p for Sx^ip. The formula T can be modelled as 
the formula self = self. A formula ip is called a sentence if it contains no free variables, 
i.e., all variables xintp occur in the scope of a quantifier 3a;. 

The language C\ extends the language with variables to denote the identities of 
states; there is additionally a special constant self that always denotes the current state. 
An atomic formula is of the form t\ = t 2 , expressing that two terms denote the same 
state. Additionally, a formula of the form 3xp expresses that there exists a state (which 
is denoted by x) for which tp holds. 

Although the syntax of the language C\ closely resembles the syntax of first-order 
modal logic [6], there is a fundamental difference in the semantics of both languages. 
In first-order modal logic, quantification is performed inside the states of a model. That 
is, each state constitutes a model in itself as it contains a domain over which the ex- 
istential quantifier 3 can quantify. However, in the present logic, the states of a model 
themselves constitute the domain of quantification. Moreover, there is a second funda- 
mental difference, namely in the range of quantification. Whereas in first-order modal 
logic, the existential quantifier ranges over the entire domain, in our logic it is restricted 
to range over a subdomain, namely over the states that are directly reachable via the ac- 
cessible relation. The ratio behind this is that for instance in the setting of multi-agent 
topologies, the accessible agents are precisely the agent whose identities are known. 
Moreover, it gives rise to a form of implicit bounded quantification that complies with 
the local character of modal logic: like one is not allowed to go from one state to an ar- 
bitrary state, only to an accessible state, one cannot instantiate variables with arbitrary 
states but only with states that are accessible. 

To obtain a framework that is as general as possible (and that perhaps can be ap- 
plied to other areas besides network topologies), we explicitly distinguish between the 
accessibility relation and the domains of quantification. That is, we introduce the notion 
of a neighbourhood relation which defines for each state the collection of states over 
which can be quantified in this state. 

Definition 6 {Structures for the language C\) 

A structure for £1 is a tuple that is of the form: 

M = {W, r, n), 

where W constitutes the domain of the structure, r C W x W denotes an accessibility 
relation on W and n C W x W denotes a neighbourhood relation on W . For each 
state w G W, we use n(w) to denote the set {u G W \ n{w,u)} of states in the 
neighbourhood. 
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A network topology is then a special type of structure, namely a structure (TL, r, n) that 
satisfies n = r and additionally w G n(w), for all w G W. Thus, network topologies 
are structures in which the neighbourhood relation coincides with the accessibility re- 
lation and each state is part of its own neighbourhood (and thus also accessible from 
itself). The rationale behind the latter requirement is that we assume that each agent in 
a network knows itself (cf. [8]). 

In order to interpret formulae from the language £i, we need to extend the truth 
definition of £i with a mechanism of interpreting variables. We achieve this via the 
standard notion of an assignment function. 

Definition 7 {Assignment function) 

Given a structure JG[ = (IT, r, n) an assignment function / is a partial function of type 
Var — > W with finite domain, which maps variables to states in the structure. The 
set (IT) consists of all assignment functions over IT. The empty assignment function, 
which is undefined for all inputs, is denoted by (). Moreover, given an assignment /, a 
state w G W and a variable x G Tor, we define the variant f[x w] of f to be the 
function defined by: 

/[^^^](^)={/(y) irwL 

where = stands for syntactic equality. 

The interpretation of terms and formulae in the language Ci are given via the following 
truth definition. 

Definition 8 {Truth definition for Ci) 

Given a structure M = (IT, r,n), a state w G IT, and an assignment / : Tor ^ IT, 
we define the interpretation of terms t in £i as follows: 

. _ f to if t = self 

wj( ) /(f) otherwise 

The truth definition A4, w, f \= ip is given by: 

■M,W, f \= {ti = t 2 ) Iw,f{tl) = Iwjih) 

M,w,f\=ipiAif2 M,w,f \= ifi and M,w,f \= if2 

M,w, f \= (}ip G r{w) : M, v,f\=(p 

f 1= 3xip € n{w) \ f[x ^ v]\= p 

Additionally, we have A4,w |= p if for all assignments / it holds that A4,w, f |= p. 
Finally, we have Af |= if for all w G IT it holds that fA,w \= p. 

Note the difference in the truth definition between the operators 0 and 3 with respect to 
the point of evaluation: in the truth definition of the former operator there is a shift in 
perspective, viz. from w to v, whereas in the latter, the point of view w remains fixed. In 
other words, 3 quantifies over the current neighbourhood while the operator 0 is used 
to change the current scope of quantification. Additionally, note that the constant self 
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constitutes a non-rigid designator [6] in the sense that its denotation differs among the 
states in a structure; in particular, in each state the denotation of this designator is the 
state itself. 

We could say that the logic C\ exhibits a separation between the mechanisms of 
structure traversal and variable instantiation', that is, the operator 0 is used to make 
shifts of perspective along the accessibility relation, while the operator 3 is employed to 
instantiate variables with states in the neighbourhood. The general set up of the semantic 
framework enables us to consider modality and quantification in isolation as well as to 
explore their interplay. For instance, we are in the position to examine to what extent the 
language C\ can express connections between the accessibility and the neighbourhood 
relation: e.g., it can express the property that the neighbourhood relation is a subrelation 
of the accessibility relation. That is, for all structures Af = (W, r, n) and states w & W 
the following holds: Jvi,w |= yx(){x = self) n{w) C r{w). Secondly, this does 
not hold the other way around; in Corollary 16, we state that there does not exist a 
formula that expresses r{w) C n{w), for all w. However, a straightforward refinement 
of the language would be an extension with the inverse operator of (), which has a 
natural interpretation in the context of network topologies, as it denotes the is-known- 
by relation. The interpretation of this operator, which we denote by is as follows: 

M,w, f ^ 3u : w e n{v) and M, v,f\=Lp. 

Given a structure Al = {W, r, n), for which we assume w G n{w), for all w G W, the 
following holds. For all states w G FF: 

M,w \= 3x{x = self A □(3y(y = self A 0“^(a: = self A Bz(z = y))))) 

<S4> 

r(w) C n{w). 

To obtain some further familiarity with the language £i, let us consider several proper- 
ties of network topologies that we can express with it. 

Example 9 

- First of all, the formula 3x{x = self), which can be thought of expressing “know- 
ing yourself”, is valid in any network topology. 

- Secondly, the formula 3x{x = self A DOa: = self) is true in a state in case all 
accessible states have in turn access to this state. In other words, it expresses “ev- 
eryone that 1 know, knows me”. 

- Additionally, the formula 3xy{^{x = y) A (}{x = self A ~^(}y = self) A 0(y = 
self A ^()x = self)) is true in a particular state, in case there are two distinct 
accessible states that are not accessible to one another. Informally, it can be thought 
of as expressing “I know two agents that do not know each other”. 

- Finally, we illustrate that quantification does not commute with modality. Consider 
the formula 3xiZ\{x = self), which is true in a state in case there is exactly one 
accessible state, and as in network topologies the accessibility relation is reflexive, 
can be thought of expressing “1 know of only myself”. On the other hand, the 
formula U3x{x = self), which can be thought of expressing “everyone that 1 
know, knows itself”, is valid in any network topology. 
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4 Semantic Characterisation 

In this section, we study the expressiveness of the extended modal language L\. In 
particular, we address the issue what properties the language can express and what 
properties are beyond its expressive power. The central restult of this study is a semantic 
characterisation of the language, which amounts to the identification of the conditions 
under which two structures satisfy precisely the same formulae of Ci. 

For the basic modal language the semantic characterisation is given by the the 
notion of a bisimulation [3,9]. That is, two structures satisfy the same modal formulae 
from £q if and only if they are related by a bisimulation.' The language £i combines 
the standard modal logic £q with a bounded quantification mechanism. In order to deal 
with variable instantiation we employ the notion of an injective sequence. 

Definition 10 (Sequences) 

- Given a set W of states, a sequence w = [wi • • • w„] over W is called injective 
if Wi = Wj implies i = j, for all 1 < i,j < n. We employ the notation \W] to 
denote the set of all injective sequences over W. Additionally, for all U C W , we 
say w G {7 \ w in case w is an element of U but does not occur in w. We use the 
notation Wi to denote the z-th element of w. Finally, [] denotes the empty sequence. 

- The operator • : [W] x FF — > [W] appends states to sequences of states; i.e., 
[wi • • • Wn] • w = [wi • • • Wnw], provided that w does not occur in [wi • • • w„]. 

Injective sequences can be thought of as abstractions of assignment functions, which 
just contain that information that is needed in the semantic characterisation. That is, 
each assignment function / : Var W , which we assume to be of finite range, can 

be represented by an injective sequence consisting of the elements in the range of / in 
some particular order. This representation thus abstracts from the particular domain of 
the function /. 

We are now in the position to define fhe notion of a history-based bisimulation, 
which exfends the notion of a bisimulation with a mechanism that handles bounded 
quantifications. For technical convenience only, we assume that the variables in formu- 
lae are bound only once.^ That is, we do not consider formulae of the form 3x{(pA3xip). 
This is not a real restriction as we can always take an alphabetic variant of these formu- 
lae: 3x{(fi A 3y(ij’[y / x])) where y is a fresh variable, which is logically equivalent. 

Definition 11 (History-based bisimulation) 

Given the models M = (FF, r-^ , n-^) and N = {U, , n^), a relation 

Z C (W X [FF]) X ({7 X [f7]) 

is called a history-based bisimulation, if (w, w)Z(u, u) implies the following: 

' Properly, this is not true; one has to assume the image finiteness property or to consider ultra- 
filter extensions. 

^ This simplifies the condition (n-bisim) in Definition 1 1 , as it allows us to restrict to extensions 
of sequences rather having to account for removals of states as well. 
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(self) w = Wj iff u = Uj 

(var) Wi G n^{w) iff Ui G {u) 

(r-bisim) if w' G r-^ (w) then 3u' G r^{u) with (w', w)Z{u', u) 

(n-bisim) if w' G n^{w) \ w then 3m' G n^{u) \ u with {w, w • w')Z{u, u • u') 

and vice versa for (r-bisim) and (n-bisim), where the roles of {w, w) and (u, u) are 
interchanged. Additionally, we define wZu to hold in case (w, \\)Z{u, []). 



Example 12 {History-based bisimulation) 

To illustrate the notion of a history-based bisimulation, let us return to the structures 
M and Af depicted in figure 3 , where we assume that the neighbourhood relation coin- 
cides with the accessibility relation. The language £i distinguishes between these two 
structures, consider for instance the formula 3 x{x = self). 

We argue that there does not exist a history-based bisimulation Z with wZv\. For 
suppose that such a relation exists then {w, [])Z(mi, []) and condition n-bisim requires 
(w, [mi])Z(mi, [m 2]) and subsequently by r-bisim we obtain (w, \w])Z{v2, [v2])- How- 
ever, this is in contradiction with condition var as w G n{w) while V2 ^ n{v2). Hence, 
we conclude that such a relation Z does not exist. 

This simple case shows why the bisimulation is called history -based: the sequences 
[w] and [M2] represent histories of states that have been encountered in neighbourhoods 
while traversing the structures AA and A\f along their accessibility relation. If the ele- 
ments of these sequences are encountered again, that is, are in the neighbourhood of the 
present state zm in Al, this should be mimicked in N, that is, are in the neighbourhood 
of the present state M2. 

If we restrict ourselves to finite structures, the notion of a history-based bisimulation is 
decidable. Note that it is crucial here that injective sequences do not contain repetitions 
of states. 

Observation 13 {Decidability of history -based bisimulation) 

Given structures A4 and Af with finite domains, for all states w G AA and u G Af, it is 
decidable whether there exists a history-based bisimulation Z with wZu. 

It is worth remarking here that the notion of a history-based bisimulation is quite differ- 
ent from the notion of a history-preserving bisimulation [ 7 ]. The latter is a very strong 
notion saying that two states are history-preserving bisimilar in case they are related by 
a bisimulation and additionally, the respective substructures consisting of the states that 
can reach the state via the accessibility relation, are isomorphic. 

Before we phrase the semantic characterisation of the language £1 in theorem 15 , 
we define the notion of an image finite state. 

Definition 14 {Image-finiteness) 

Given a structure Avi = {S, r, n) we let r* denote the reflexive, transitive closure of r. 
A state ZM G S' is called r -image finite if m(m) is finite for all v with (zm, m) G r*, and is 
called n-image finite if n{y) is finite for all v with (zm, m) G r*. Moreover, zm is called 
image finite if it is both r-image finite and zz-image finite. 
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Properly, we do not need the assumption of image-finiteness, as analogous to the proof 
of the semantic characterisation of standard modal logic, we could use ultrafilter exten- 
sions [3]. However, for the sake of simplicity we adopt this property here. 

Theorem 15 {Semantic characterisation) 

Given two structures M and Af, for all states w from AA and u from AA the following 
holds: 

(i) if wZu for some history-based bisimulation Z then for all sentences (p € £i we 
have A4,ivl=(p-^A/,ul=(p 

(a) if w, u are image finite and AA,w \= (p AA, u \= ip for all sentences p> G Li, 
then wZu for some history-based bisimulation Z. 

Because of space limitations, we do not give a proof of this non-trivial result. Instead, 
we consider some applications of the result. First of all, consider the models AA and 
AA from Figure 1, where we assume that the accessibility relation and the neighbour- 
hood relation coincide. The language £i cannot distinguish between these models. This 
follows from the fact that there exists a history-based bisimulation between AA , w and 
AA, w. Secondly, the language £i cannot express the property that the accessibility re- 
lation is contained in the neighbourhood relation, as stated in the following result. 

Corollary 16 There does not exist a formula (p G Ci such that for all structures AA = 
(yV, r, n) and states w gW we have: AA,w \= tp r{w) C n{w). 



5 Decidability 

In this section, we discuss the decidability of the language £i. 

5.1 The Guarded Fragment 

In this section, we examine the connection of our logic with the guarded fragment of 
first-order logic [1]. This logic, which satisfies the property of being decidable, consists 
of first-order formulae that are build from arbitrary atoms, boolean operators and finally, 
quantifications of the following format: 

3y(i?yxA(^(x,y)), 

where i? is a particular predicate and y and x are sequences of variables. The semantic 
characterisation of the guarded fragment is defined in terms of a guarded bisimulation. 
That is, any formula ip is equivalent to a formula in the guarded fragment if and only if 
ip is invariant for guarded bisimulations. This notion is defined below. 

Definition 17 A guarded bisimulation befween two models AA and A/" is a non-empty 
set F of finite partial isomorphisms that satisfies the following conditions. For all / : 
AT — > y in F, we have 

- for all guarded sets Z in AA there exists p in F with domain Z such that g and / 
agree on X H Z 
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- for all guarded sets W m N there exists g in F with range W such that g ^ and 
f~^ agree onY nW 

where a set V is called guarded in a model in case there exist ai , . . . , a„ (with rep- 
etitions, possibly) such that V = {ai, . . . , a„} and for some relation i? we have that 
i?(ai, . . . , a„) is true in the model. 

We argue that £i does not fall inside the guarded fragment. Consider the two struc- 
tures A4 and JY in Figure 2. The set F consisting of the partial isomorphisms {w 
V, wi ui} and {w v,W2 ui} constitutes a guarded bisimulation between Ad 
and Af. Hence, there is no formula in the guarded fragment that distinguishes between 
these two structures. However, in our language £i there is for instance the formula 
Ip = (3a;3g(^a; = y)) with A4,w ^ ip and M,u ^ ip- So, ip & C\ is not invariant 
for guarded bisimulations and therefore is not equivalent to a formula in the guarded 
fragment. So, we establish the following result. 

Observation 18 {Relation with guarded fragment) 

The language C\ is not contained in the guarded fragment of hrst-order logic. 

5.2 Hybrid Languages 

Our framework has connections with the work on what are called hybrid languages, 
which are languages that like £i also combine modality with hrst-order quantihcation 
mechanisms [4,2]. In particular, hybrid languages extend the basic modal language Cg, 
with a collection of nominals that are used to label states in models. These nominals are 
propositional formulae that are true at exactly one state in a model, and so to speak are 
employed as global unique names for states. Further extensions additionally incorporate 
operators of the form to jump to the state that is denoted by the nominal i, as well as 
operators to bind nominals. Here we consider the two fundamental ones of these binding 
operators; viz. the hybrid operator J, x and the hybrid existential quantiher, which we 
denote as 3x to distinguish it from the quantiher 3a; from C\. 

First of all, the quantiher J, x binds the variable x to the current state of evaluation. 
It can be dehned in the language C\ as follows: 

[xLp = 3x{x = self A (p) . 

Moreover, it corresponds to existential quantihcation in the class of structures in which 
the neighbourhood of states is given by the state itself; that is, in the class: 

{Ad I Ad 1= 3x{x = self A Vg(g = a;))}. 

Additionally, the hybrid quantiher 3a; ranges over the entire set of states in a struc- 
ture. If we consider this operator in our framework, it corresponds to existential quan- 
tihcation in the class of structures in which the neighbourhood relation is universal, 
meaning that each state is in the neighbourhood of any other state. This class can be 
dehned as follows: 



|(VF,r,n) \n = W xW}. 
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The language L\ is not expressive enough to characterise the above class of models, as 
this type of existential quantification assumes an external view on models rather than 
the local view that has been taken in our framework. 

Finally, we mention the hybrid operator @3, that is used to jump to the state denoted 
by the variable x. The truth definition of this operator can be given as follows: 



This operator has no counterpart in our framework due to the fact that in each state, 
it allows going to states that are not necessary reachable via the accessibility relation. 
This is in contrast with one of our underlying assumptions, saying that in a state one 
cannot go to arbitrary states but only to an accessible one. 

5.3 Finite Model Property and Decidability 

The language £1 does not satisfy the finite model property, which is due to the fact that 
it can compel infinite neighbourhoods. Let y) stand for the formula: 



which expresses that from the accessible state x the state y is accessible. Subsequently, 
let ip denote the conjunction of the following formulae 3 x{x = x), which expresses that 
a neighbourhood is nonempty, Vx(^R(x, x)) expressing the irreflexivity of the relation 
i?, \/x'iy\/z{(R(x, y) A R{y, z)) R{x, z)) denoting transitivity and yx 3 y{R{x, y)) 
expressing seriality. If this formula is true in a particular state w then the neighbour- 
hood of this state is infinite. The construction of this neighbourhood {ui, U2, U3, . . .} is 
sketched in figure 4 . 



Moreover, it follows that the validity problem of the the language C\ is undecidable. 
In fact, this is a direct consequence of the result claimed in [ 2 ], which says that the 
hybrid language consisting of the basic modal language £q extended with variables and 
the operator J, x, is undecidable. The claim then follows from the fact that this hybrid 
language is a sublanguage of £1 ; i.e., hybrid formulae of the form J, xp can be modelled 
in £1 as 3 x{x = self A p). 

The interesting question now arises of the role of the constant self in this result. Cur- 
rently, we are investigating the expressivity and complexity of the language £1 without 
this constant. Here, we only mention that this sublanguage does not satisfy the finite 



M,w,f \= M,f(x),f ^ p. 



(){x = self A Oy = self) 



w 




Fig. 4. An infinite neighbourhood 
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model property either, which can be shown in a similar manner as above, using the 
following definition; 

R{x,y) = 0(3u(u = a;) A 0(3m(m = y))). 

Thus, R{x, y) expresses that y is known in a state that can be accessed from some 
accessible state (with respect to the current state) in which x is known. 

6 Topologies of Multi-agent Systems 

In this section, we consider an application of our logic to the description of multi-agent 
topologies. More specifically, we show how our basic notion of quantification can be 
used in reasoning about the ambiguities of names', that is, situations in which one agent 
is known by other agents under different names. 

Formally, we extend our language £i with a countable set C of names, with typical 
element c. A term t in the extended language, which is called C 2 , is thus either a variable 
x, the constant self, or a name c G C. Formulae are defined as in Definition 5 and they 
are interpreted over the following structures. 

Definition 19 A multi-agent topology over the set of names C is a structure: 

(VF,r,/), 

where FF is a set of states, or agents, r Q W x W denotes the accessibility relation, 
and / is a total function which assigns to each w G W an interpretation I {w) of each 
name c G C, that is, I{w) G C ^ W. 

The definition of the truth of a formula ip in the extended language £2 involves a 
straightforward adaptation of the truth definition of the language £1 and is therefore 
omitted. Instead, we explain here the use of quantification in the description of the am- 
biguities to which names may give rise. First, we observe that without quantification 
we cannot describe phenomena like that one agent is known by different agents under 
different names. For example, given an agent w, we cannot describe the situation that 
I{w){c) = I{w'){c), for some (w,w') G r, simply because the modal operators in- 
duce a “context switch”, that is, a different interpretation of the names. However this 
situation can be described using quantifiers simply by the formula: 

3x{x = c A 0(a; = c)). 

So, we bind the value of the constant c to the variable x, and use the fact that the 
interpretation of the variables is fixed, that is, does not change when “moving” from 
one agent to another. 

In practice, we may assume without loss of generality that the set C of names 
is finite. Under this assumption we can, without loss of expressive power, restrict to 
bounded quantification of the form: 

3x{x = c A ip). 

For this language the validity problem is decidable. We are currently working on a 
decision procedure that is based on a semantic tableau construction. 
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7 Future Research 

Many issues remain to be studied such as expressivity and complexity results and the 
development of a complete axiomatization of (sublanguages of) the language L\. Other 
topics of interest include the introduction of predicates to describe properties of agents, 
for example properties expressing security aspects. Additionally, we want to investigate 
the introduction of the inverse and the reflexive, transitive closure 0* of the oper- 
ator 0 for describing properties of network topologies. A final issue is the study of the 
connection with epistemic logic [12]. 
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Abstract. The beliefs of the agents in a multi-agent system have been formally 
modelled in the last decades using doxastic logics. The possible worlds model and 
its associated Kripke semantics provide an intuitive semantics for these logics, 
but they commit us to model agents that are logically omniscient. We propose 
a way of avoiding this problem, using a new kind of entities called subjective 
situations. We define a new doxastic logic based on these entities and we show 
how the belief operators have some desirable properties, while avoiding logical 
omniscience. A comparison with two well-known proposals (Levesque’s logic of 
explicit and implicit beliefs and Thijsse’s hybrid sieve systems) is also provided. 

1 Introduction 

In the last decade doxastic modal logics have been considered the most appropriate for- 
mal tool for modelling the beliefs of the agents composing a multi-agent system ([1]). 
The standard way of providing a meaning to the modal formulas of these logics is to 
use the possible worlds model ([2]) and its associated Kripke semantics ([3]). This se- 
mantics is quite natural and intuitive, but it is well known that the agents modelled in 
this framework are logically omniscient ([4]). Therefore, this semantics is unsuitable 
to model the beliefs of realistic, non-ideal agents. The aim of our work is to provide a 
plausible way of modelling the beliefs of non-logically omniscient agents, while keep- 
ing the essence and the beauty of the possible worlds model and the Kripke semantics. 

This article^ is structured as follows. In section 2 we give an intuitive explanation 
of our approach to the logical omniscience problem, which is based in a new kind of 
entities called subjective situations. In a nutshell, a subjective situation is the perception 
that an agent has of a certain state of affairs. These situations, as will be explained 
below, will take the role of possible worlds. In section 3, a formalization of subjective 
situations in the framework of doxastic propositional logic is made. Section 4 is devoted 
to a study of the behaviour of the modal belief operators, that extends and generalizes 
our previous results ([5]). It is shown how their properties do indeed correspond with 
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our intuitions about what should be an adequate formalization of the doxastic attitude of 
a non-ideal, non-logically omniscient agent. In section 5, a comparison of our proposal 
with two well-known approaches (Levesque’s logic of explicit and implicit beliefs ([6]) 
and Thijsse’s hybrid sieve systems ([7])) is performed. The paper finishes with a brief 
summary and the bibliographical references. 



2 Motivation of Subjective Situations 

The most popular way of dealing with the logical omniscience issue is to change the 
concept of what a possible world is (see [8] for a detailed review of the most interesting 
approaches to the problem of logical omniscience). Regardless of the way in which the 
concept of possible world is modified, there is a kernel that never changes: the formal 
representation of a possible world is not related in any way with the notion of agent. 
Thus, it may be said that all the approaches in the literature present an objective view 
of what a possible world is (i.e. a world is the same for all the agents, is independent 
of them). In a standard Kripke structure, the only item that depends on each agent is its 
accessibility relation between possible worlds. 

The traditional meaning assigned to the accessibility relation Ri of an Agenti is that 
it represents the uncertainty that Agenti has about the situation in which it is located 
{e.g. (wqR^wi) means that Agents cannot distinguish between worlds wq and wi). 
This situation is quite peculiar, because the formulae that are true in two worlds that are 
linked by an accessibility relation are, in principle, totally unrelated (i.e. given a Kripke 
structure, there is no relationship between the accessibility relation between states and 
the function that assigns truth values to the basic propositions in each of them). 

Our proposal may be motivated by the following scenario. Imagine two people (a 
and /?) that are watching a football match together. In a certain play of the game, a fault 
is made and the referee awards a penalty kick, a thinks that the referee is right, because 
it has noticed that the fault was made inside the penalty area (let us represent this fact 
with proposition F); at the same time, /3 is thinking that the referee was wrong because, 
in its perception of the situation, the fault was made just an inch outside the penalty area. 
How can this situation (and the beliefs of the two agents) be formally represented? 

Following the standard approach, we could model the fact that a believes F and (3 
believes ^F by assuming that in all the (objectively described) worlds considered as 
possible in the current state by a the proposition F holds, whereas in all the worlds 
considered as possible by (3 (/3’s doxastic alternatives) F is false. This account of each 
agent’s doxastic state does not seem very satisfactory to us, at least for two reasons: 

- It does not tell us how each agent’s perception of the situation influences in its own 
beliefs. An agent is supposed to eliminate instantly from its set of doxastic alterna- 
tives all those (completely specified) possible worlds in which a basic proposition 
has a truth value that does not match the agent’s current beliefs. It would be more 
plausible to have a framework in which the agent kept a partial description of the 
situation in which it is located, and in which it could use the facts that it keeps 
perceiving from the environment in order to keep increasing and refining its beliefs 

([9], [10]). 
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- Assuming that the fault was indeed made inside the penalty area, most philosophers 
would argue that a not only believes P but also knows it (being P true in the real 
world), whereas f3 believes ^P but can not possibly know ^P, being it actually 
false^. Thus, in a somehow magical way, one agent would have some knowledge 
(that would coincide with reality) whereas the other wouldn’t. 

In our opinion, this state of affairs (the actual situation, comprising both the football 
match and the agents, along with their beliefs) may not be adequately described with a 
simple assignment of truth values to the basic propositions. Even if we had an accurate 
description of the real world, does it really matter very much whether the fault was 
made inside the penalty area in order to model the beliefs of the two agents involved in 
the scene? 

The situation (s) is obviously the same for the two agents a and j3 (they are watching 
the same match together). From a’s point of view, the description of s should make 
true proposition P; however, from /3’s perspective, in the present situation P should be 
considered false. Obviously, there would be many aspects of s in which a and /? would 
agree; e.g. both of them would consider that the proposition representing the fact “We 
are watching a football match on TV” is true in s. 

As far as beliefs are concerned, we argue that, in this situation, a should be capable 
of stating that BaP (a has seen the fault and has noticed that it was made inside the 
penalty area; thus, it believes so). It would not seem very acceptable a situation in which 
a perceived the fault to have been made inside the penalty area and defended that it did 
not believe that a penalty kick should have been awarded (the only possible explanation 
being that a is a strong supporter of the offending team). It also seems reasonable to 
say that a cannot fail to notice that it believes that the fault was made inside the penalty 
area; thus, a may also assert in s that B^BaP. In a similar way, in this situation f3 
cannot state that Bf^P {f3 cannot defend that it believes that the referee is right, in a 
situation in which it perceived the fault to have been made outside the penalty area). 
Thus, it seems clear that each agent’s point of view on a situation strongly influences 
(or we could say even determines) its positive and negative beliefs in that situation. 

In our framework we want to include the intuition that agents are smart enough 
to know that other agents may not perceive reality in the same way as they do. In the 
previous example, without further information (e.g. a shouting “Penalty!”), (3 should 
not be capable of supporting (or rejecting) that B^P', analogously, a could not affirm 
(or deny) that BjsP. That means that the communication between the agents is the main 
way in which an agent may attain beliefs about other agent’s beliefs. We could have 
chosen other alternatives; for instance, we could have stated that an agent believes that 
the other agents perceive reality in the same way as they do, provided that they do not 
have information that denies that fact. If that were the case a would assume that (3 also 
believes that P is true, as far as it does not have any reason not to think so (e.g. (3 saying 
“This referee is really blind”). 

^ It could be argued that we are somehow neglecting the need of a justification for the belief 
in order for it to become knowledge (as knowledge is usually defined in the philosophical 
literature as true justified belief). But, what could possibly count more as a justification that 
each agent’s own direct perception of the situation? 
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A final reflection on the meaning of the accessibility relation between situations 
for Agenti (Ri) is necessary. It will be assumed that an agent cannot have any doubts 
about its own perceptions and beliefs in a given state. E.g. if, in situation s, a looks at 
the match and thinks P, then it surely must realise this fact and believe P in s (and even 
believe that it believes P, were it to think about that). Thus, if Ra links s with all those 
situations that a cannot tell apart from s, it must be the case that a also perceives P as 
true in all those states as well (otherwise, those states would be clearly distinguishable 
by a, because in some of them it would support P whereas in some of them P would 
be rejected). The only uncertainty that a may have is about the perception of s by the 
other agents. In the example, a does not know whether it is in a situation in which f3 
supports P or in a situation in which f3 rejects P. Therefore, a’s accessibility relation 
must reflect this uncertainty. 

Summarising, the main points that have been illustrated with the previous discussion 
are the following: 

- A situation may be considered not as an entity that may be objectively described, 
but as a piece of reality that may be perceived in different ways by different agents. 
Thus, it is necessary to think of a subjective way of representing each situation, in 
which each agent’s point of view is taken into account. In the previous example, 
the description of s should include the fact that a is willing to support P, whereas 
j3 isn’t. 

- An agent’s beliefs in each situation also depend on its point of view. 

In the situation of the example, PqP would hold from a’s perspective, whereas 
it would not be either supported or rejected by (3. Thus, we argue that it does not 
make sense to ask whether B^P holds in s or not; that question must be referred to 
a particular agent’s point of view. 

- The interpretation of the meaning of each agent’s accessibility relation is slightly 
different from the usual one. 

Each accessibility relation Ri will keep its traditional meaning, i.e. it will represent 
the uncertainty of Agenti with respect to the situation in which it is located. How- 
ever, our intuition is that an agent may only be uncertain about the other agents’ 
perception of the present state, not about its own perception. 



3 Formalization of Subjective Situations 

These intuitive ideas are formalized in the structures of subjective situations: 

Definition 1 (Structure of Subjective Situations) 

An structure of subjective situations forn agents is a tuple 

< S', Pi,...,P„,Ti,...7ji,Pi,...,P„ >, where 

— S is the set of possible situations. 

— Ri is the accessibility relation between situations for Agenti. 

— Pi is a function that returns, for each situation s, the set of propositional formulae 
that are perceived as true by Agenf in s. 
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- Ti is a function that returns, for each situation s, the set of propositional formulae 

that are perceived as false by Agenti in s. 

£ is the set of all structures of subjective situations. 

The presence of % and Ti allows Agenti to consider partial situations (those in 
which Agenti does not have any reason to support or to reject a given formula) as well 
as inconsistent situations (those in which Agenf may have reasons to support and to 
reject a given formula). This kind of situations was already considered by Levesque in 
his logic of explicit and implicit beliefs ([6]). A detailed comparison of our proposal 
and that of Levesque is offered in section 5. 

The accessibility relation between situations for Agenti has to reflect its uncertainty 
about the way in which the actual situation is perceived by the other agents. Thus, Ri has 
to link all those states that Agenti perceives in the same way but that may be perceived 
in different ways by other agents. This intuition is formalized in the following condition: 

Definition 2 (Condition on Accessibility Relations) 

\/s,teS, (sRit) if and only if{%{s) = %{£)) and {tFi{s) = tFi{t)) 

This condition implies that the accessibility relations are equivalence relations. This 
result links this approach with the classical Sb modal system, in which this condition 
also holds. In 55 the presence of this condition makes true axiom 4 (positive intro- 
spection), axiom 5 (negative introspection) and axiom T (the axiom of knowledge); the 
modal operators of the system proposed in this article will have similar properties, as 
will be shown in section 4. 



3.1 Satisfiability Relations 

A simplified version of the doxastic propositional language for n agents is considered, 
as shown in the following definition: 

Definition 3 (Doxastic Modal Language £) 

Consider a set of modal belief operators for n agents (Bi, ..., Bn). C is the lan- 
guage formed by all propositional formulae (built in the standard way from a set V 
of basic propositions and the logical operators ->,V,A,^), preceded by a (possibly 
empty) sequence of (possibly negated) modal operators. Cpc A the subset of C that 
contains those formulae that do not have any modal operator. The modal formulae of C 
are called linearly nested. 

Thus, the language C contains formulae such as P, B^Q, BiB^(R V T), B^^B 2 S 
and -^BiBi^T, but it is not expressive enough to represent formulae such as (B 2 P — > 
B^Q) or (P V B^Q). In most practical applications, an agent in a multi-agent system 
will only need to represent what it believes (or not) to be the case in the world and 
what it believes (or not) that the other agents believe (or not). This is just the level of 
complexity offered by linearly nested formulae. 
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In an structure of subjective situations each Agenti may have positive and negative 
information about some propositional formulae (given by and Ti, respectively). This 
allows us to define two relations (of satisfiability, \=i, and unsatisfiability, =|i) between 
situations and formulae for each Agenti. Given an structure of subjective situations E 
and a situation s, the expression E,s \=i (j> should hold whenever Agenti has some 
reason to think that (j) is true in situation s. Similarly, E,s =\i (j> should hold whenever 
Agenti has some reason to reject (j) in situation s. 

Notice that E,s ^i (f> should not imply that E,s ^i (j> (i.e. Agenti not having any 
reason to support (j) does not mean that it must have reasons to reject it). In the same 
spirit, E,s \=i 4> should not imply that E,s y^i (j> (Agenti could have reasons both to 
support and to reject a certain formula in a given situation). These facts will indeed be 
true, as will be seen in the next section, due to the presence of partial and inconsistent 
situations commented above. 

The clauses that define the behaviour of these relations are shown in the following 
definition: 

Definition 4 (Relations \^i and =|i) 

- yEeS,yseS,yagent i,y<j)e£pc 

E,S \=i (j><^ <j>€%{s) 

E,s ^i (j>-^ <t>eEi{s) 

- '^Ee£,yseS,yagents i,j,y<j)e£ 

E, s \=i Bj(f> WteS {(sRit) implies E, t \=j (f>) 

E, s =\i Bj4> 3teS {(sRit) and E, t =|y (j)) 

- '^EeS, ^seS, '^agents i,j,y<j)e£ 

E, s \=i ~^Bj(j) f;, s =|j Bj(j) 

E, s =|i ~^Bj(j) E,s \=i Bj(f> 

A propositional formula (j) is supported in a given situation s by an Agenti if and 
only if Agenti has reasons to think that (j) is true in s. Analogously, <j) will be rejected 
if and only if there are reasons that support its falsehood (recall that a formula may be 
both supported and rejected in a given situation). As far as beliefs are concerned, in a 
given situation s, Agenti supports that Agent j believes (j) just in case Agent j supports 
<j) in all the situations that are considered possible by Agenti in s (Agenti’ s doxastic 
alternatives). Similarly, Agenti may reject the fact that Agent j believes <j) if it may 
think of a possible situation in which Agent j rejects (j). Finally, Agenti will support 
that Agent j does not believe (j) if it may reject the fact that Agent j believes (j). We do 
not need more clauses to define fhe behaviour of fhe satisfiability and unsatisfiability 
relationships due to the restriction to linearly nested formulae imposed in definition 3. 
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4 Properties of the Belief Operators 

The definition of an structure of subjective situations, the fact that the accessibility 
relations are equivalence relations and the clauses that describe the behaviour of the 
satisfiability (and unsatisfiability) relations compose a framework in which the modal 
belief operator of each Agenti has several interesting logical properties (that, in our 
opinion, make it an appropriate operator to model the notion of belief for a non-ideal 
agent). Some of these properties are described in this section. 

4.1 General Results 

Proposition 1 (Lack of Logical Omniscience) 

In the framework of subjective situations, none of the following forms of logical 
omniscience ([8]) holds: 

- Full logical omniscience. 

- Belief of valid formulae. 

- Closure under logical implication. 

- Closure under logical equivalence. 

- Closure under material implication. 

- Closure under valid implication. 

- Closure under conjunction. 

- Weakening of beliefs. 

- Triviality of inconsistent beliefs. 

Proof. Let us take a state s in which Ti{s) = {P, {P ^ Q), ^P} and Fi{s) = {P}. 
Consider an structure for subjective situations E that only contains the situation s. 

- E,s \=i BiP and E,s \=i Bi{P Q) hold, but E,s \=i BiQ does not hold. 
Therefore, neither full logical omniscience nor closure under material implication 
hold. 

- E,s\=i Bi{Q V ^Q) does not hold. Therefore, there is no belief of valid formulae. 

- E,s \=i BiP holds, but E,s \=i Bi{P V Q) does not hold. Therefore, closure 
under logical implication and weakening of beliefs do not hold. 

- E,s \=i Bi{P Q) holds, but E,s \=i Bi{^Q — > ~^P) does not. Therefore, 
beliefs are not closed under logical equivalence or under valid implication. 

- E,s \=i BiP and E, s \=i Bi{P Q) hold, but the expression E, s \=i Bi{P A 
{P ^ Q)) does not hold. Therefore, there is no closure under conjunction. 

- E,s \=i BiP and E, s \=i Bi^P hold, but E, s \=i BiQ does not hold. Therefore, 

there is no triviality of inconsistent beliefs. □ 

There are two basic reasons that account for the failure of all these properties: 

- 7) and Ei are defined on sets of (arbitrary) formulae (not on basic propositions). 

- 7) and Ei are unrelated. Thus, a given formula may belong to both sets, to only one 
of them or to none of them. 
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It is possible to impose any of the above properties on the belief operators by re- 
quiring these sets of formulae to satisfy some conditions (for instance, if {<j> A ip)e%{s) 
implies that (j)e%{s) and ipeTi{s), then Agenti’s belief set would be closed under con- 
junction). 

Proposition 2 (Relation between |=* and =|t) 

For any linearly nested formula f 
E,s (j) does not imply E,s =\i 4> 

E, s \=i 4> does not imply E, s 4> 

Proof: Take the structure of subjective situations E described in the proof of the 
previous proposition. It is easy to check these facts: 

- E,sY=i BiR and E, s fji BiR. Therefore, E,sY=i <j> does not imply E, s =|i f. 

- E,s \=i BiP and E, s =|i BiP. Therefore, E,s \=i <j) does not imply E, s f\i 

(j). □ 



4.2 Results on Positive Introspection 

Proposition 3 (Characterization of positive beliefs) 

For any linearly nested formula <f>, 

E,s \=i 4> if and only if E, s \=i Bif 

Proof: The if side of the formula coincides with proposition 4. The only if side may 
be proven as follows: 

E,s \=i Bif \/t{sRit), {E,t \=i (f>). As Ri is reflexive, (si?is); therefore, 

E, s \=i f. □ 

This result states that Agentt believes f in state s if and only if f is one of the 
facts that is supported by Agenti in that state^. Thus, in our framework the difference 
between belief and knowledge vanishes: both concepts have to be understood as the 
propositional attitude that the agents adopt towards those formulae that they perceive 
to be true in the environment. Therefore, the (rather philosophical) difference between 
those beliefs that are true in the real world (that constitute knowledge) and those that 
are not (plain beliefs) is not taken into account. 

Proposition 4 (Belief of supported formulae) 

For any linearly nested formula (j), 

E, s \=i (j) implies E, s \=i Bif 

Proof. There are five cases to be considered: 

- (/) is a propositional formula. 

s |=i (/) and (/) is propositional (f>eTi{s) yt{sRit), feTif) 

\/t(sRit),E,t |=j f E,s |=j B^f 



^ The “only if” side of the proposition is the classical axiom of knowledge, axiom T. 
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- If (/) is a modal formula that starts with an affirmed belief operator Bi (i.e. (f> = 
Bi-tp), this fact is exactly the next proposition. 

- If (/) is a modal formula that starts with an affirmed belief operator Bj (i.e. (p = 
Bjip), this statement coincides with proposition 6, that will be proved later. 

- If (/) is a modal formula that starts with a negated belief operator Bi (i.e. (p = 
^Bipi), this fact is the one proved as proposition 10. 

- If (/) is a modal formula that starts with a negated belief operator Bj (i.e. (p = 

-^Bjtp), this fact is the one proved as proposition 11. □ 

This proposition is telling us that an agent believes all formulae that it has reasons to 
support, as suggested in the motivating example. However, this proposition has an added 
value over our intuitions, because it refers to any kind of linearly nested formulae, and 
not only to propositional formulae. 

Proposition 5 (Single-agent positive introspection) 

For any linearly nested formula (p, 

E, s \=i Bip implies E, s \=i BiBip 

Proof: If E, s \=i Bip, that means that E^s \=i p holds in all the situations Ri- 
related to s. Being Ri an equivalence relation, these situations are exactly the ones 
included in the equivalence class of s induced by Ri. This class is also the set of situa- 
tions that may be accessed from s in two steps (in fact, in any number of steps) via Ri, 
and p is supported by AgenU in all of them. Thus, V s' {sRis')\/ s” {s' Ris”) E , s" \=i p, 
and E, s \=i BiBip also holds. □ 

This proposition states that axiom 4 (the classical axiom of positive introspection) 
holds for each belief operator Bi (i.e. every agent has introspective capabilities on its 
own positive beliefs). 

Proposition 6 (Generation of positive beliefs) 

E, s \=i Bjp implies E, s \=i BiBjp 



Proof: E,s \=i Bjp yt{sRif),E,t \=j p. Thus, E,t \=j p holds in all 

the worlds t that belong to the same equivalence class that s (considering the partition 
defined by Rp. Therefore, in all the worlds accessible from s via Ri in any number n 
of steps, E, t \=j p. Taking the case n = 2, we obtain that E, s \=i BiBjp. □ 

If an agent has reasons to support a certain belief of another agent, then that belief 
will be included in its belief set. 

Proposition 7 (Inter-agent positive introspection) 



E, s \=i Bjp implies E, s \=i BjBjp 



Proof: E, s \=i Bjp \/t{sRit), E, t \=j p. Using the result given in proposi- 
tion 4, that formula implies that Wt{sRit), E, t \=j Bjp-, thus, E, s \=i BjBjp. □ 

This result is more general (proposition 5 reflected the case i = j). It states that 
each agent is aware of the fact that the other agents also have introspective capabilities. 
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Proposition 8 (Multi- agent positive introspection) 

It does not hold (for three different agents Agenti, Agent j and Agent k and a lin- 
early nested formula (j>) that 



E, s \=i Bjf implies E, s \=i BkBjf 



Proof. We will show a counterexample. Take an structure for subjective situations E 
with two situations, s and t, such that (sRkt) holds, but (sRit) and (sRjt) do not. Take 
a formula f such that feTj (s) and f fTj (t). In this state of affairs, E, s \=i Bjf holds 
but E, s \=i BkBjf does not hold. □ 

This proposition states a negative result. It is telling that even if Agenti has reasons 
to support that Agent j believes something, that is not enough for Agenti to think that 
any other Agentk will have that belief. This proposition is essentially expressing the 
uncertainty of Agenti about the beliefs of a different Agentk- 

4.3 Results on Negative Introspection 

Proposition 9 (Characterization of negative beliefs) 

For any linearly nested formula f, 

E^s =\i (j) if and only if E, s \=i ^Bif 

Proof: The if side of the proposition may be proven as follows. As we know that 
E,s ^i (j) and (sRis), it maybe said that 3t{sRit), E, t =|i f. Therefore, E, s =|i Bif, 
which is equivalent to E, s \=i ^Bif. 

The only if side of the proposition (i.e. E, s \=i ^Bif implies E, s =|i f) will be 
proved considering hve different cases (as we did in the proof of proposition 4): 

- (j) is a propositional formula. 

E, s \=i -^Bif E, s =|i Bif 3t{sRit), E, t =|i f. As f is propositional, 
E,t =\i f implies that (j)eEi{t); as (sRit), (f>eEi{s). Therefore, E, s =|i f. 

- (j) is a modal formula that starts with an affirmed belief operator Bi (i.e. f = Bitp). 

E, s \=i ^Bif E, s \=i ^BiB^-f E, s =|i B^Bif) 

3t{sRif), E, t =|i Biip u{sRif), (fRiu), E, u =|i fi. 



As Ri is transitive, {sRA) and (tRiu) imply that (sRiu). Thus, we may state that 
3u{sRiu), E, u =|i if. Therefore, E, s =|i Biif, which is equal to E, s =|i f. 

- (/) is a modal formula that starts with an affirmed belief operator Bj (i.e. <j) = Bj-tp). 

E, s \=i ^Bif E, s \=i ^BiBjip E, s =|i B^Bjip 
3t{sRif), E, t =\i Bjip 3t, u{sRif), (tRiu),E, u =\j tp. 

As Ri is transitive, {sRA) and ptRiu) imply that (sRiu). Thus, we may state that 
3u{sRiu), E, u =|j Ip. Therefore, E, s =|i Bjtp, which is equal to E, s =|i (p. 

- (pis a modal formula that starts with a negated belief operator Bi (i.e. <p = -^Bitp). 
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E, s \=i ^Bi4> E, s \=i ^Bi^Bi^p E, s =\t B^^B^pj : 
3t{sR^t), E, t =ji ^Bi^p 3t{sR^t), E, t \=i B^-ip 
3t{sRit)\/u{tRiu), E,u \=i ip. 



In this expression, t is a world that belongs to the same class of equivalence than 
s (according to the partition defined by Ri), and u represents all the worlds that 
belong to t’s class of equivalence; thus, u ranges over all the worlds belonging to 
s’s class of equivalence (all the worlds that are accessible from s via Ri in any 
number n of steps). If we take n = 1, we get that \/t{sRit), E,t \=i ip. Thus, 
E, s \=i Biip, which is equivalent to E, s =|i ^Biip. Therefore, E, s =|i (p. 

- (pis a modal formula that starts with a negated belief operator Bj (i.e. <p = ^Bjtp). 

E, s \=t ^Bi<p E, s \=t ^Bi^Bjtp 
E, s =|j Bi^Bjip 3t{sRit),E, t =1* ^Bj-ip 
3t{sRit), E,t \=i Bjip 3t{sRit)yu{tRiu), E,u \=j tp. 



In this expression, f is a world that belongs to the same class of equivalence than 
s (according to the partition defined by Ri), and u represents all the worlds that 
belong to fs class of equivalence; thus, u ranges over all the worlds belonging to 
s’s class of equivalence (all the worlds that are accessible from s via Ri in any 
number n of steps). If we take n = 1, we get that \/t{sRit), E,t \=j ip. Thus, 
E, s \=i Bjip, which is equivalent to E, s =|i ^Bj^p. Therefore, E, s =|i (/). □ 

Agenti does not believe ^ at s if and only if <p is one the facts that is rejected by i 
at s. Again, this proposition agrees with the intuitions that we had in the example that 
was used to motivate the need for the framework of subjective situations. 

Proposition 10 (Single-agent negative introspection) 

E, s \=i ^Bi<p implies E, s \=i Bi^BiCp 



Proof: E, s \=i ~^Bi(p E, s =|i Bi<p 3t{sRit), {E, t =|i (p). Thus, there ex- 
ists at least one world (say w) such that (sRiw) and E,w =|i (p. In order to prove 
the proposition, we have to notice that Ri is Euclidean (i.e. whenever {sRit) and 
(sRiu), ptRiu) also holds)"*. Therefore, w is Ri accessible from all worlds that are 
Ri accessible from s, and we may state that \/t{sRit), ptRiw) and E, w =|i (p. Thus, 
yt{sRit) 3u{tRiu)E,u =|i (p. Thus, yt(sRit) E,t =|i Bi(p, which is equivalent to 
yt{sRit) E, t \=i ^Bi(p. Therefore, we have shown that E, s \=i Bi^Bi<p. □ 

This proposition states that axiom 5 (the classical axiom of negative introspection) 
holds for each belief operator Bi (i.e. every agent has introspective capabilities on its 
own negative beliefs). 

Proposition 11 (Generation of negative beliefs) 

E, s \=i ^Bj<p implies E, s \=i Bi^Bj<p 
* It is easy to prove that any relation that is symmetric and transitive is also Euclidean. 




Avoiding Logical Omniscience by Using Subjective Situations 295 



Proof: E, s \=i E, s =|i Bjf 3t{sRit), E, t =|j f. Let us call w to 

any of the worlds referred to by this existential quantifier. Being Ri Euclidean, we know 
that therefore, we may say that i?, M =|y Thus, 

yt{sRit),E,t =|i which is equivalent to Vf(si?if), S, f \=i Therefore, 

E, s \=i B^^Bj(t). □ 

This proposition is expressing the fact that Agenf can make positive introspection 
on negated beliefs of other agents. 

4.4 Summary of the Main Properties 

Summarising the main results shown in this section; 

- All forms of logical omniscience are avoided. 

None of the restricted forms of logical omniscience usually considered in the lit- 
erature holds in the framework of subjective situations. This result is due to the 
presence of partial and inconsistent situations and to the fact that the description 
of a situation is formed with positive and negative information about propositional 
formulae (and not about basic propositions). 

- Each agent is aware of its positive and negative beliefs, and is also aware of the fact 
that the other agents enjoy this introspective capability. 

However, an agent is uncertain about the way the present situation is perceived by 
other agents and, therefore, it is unable to know anything about the other agent’s 
beliefs. 

- The positive and negative beliefs of an agent in an state reflect, as our intuitions 
suggested, the facts that are taken as true or false by the agent in that state. 

Thus, an agent’s perception determines its beliefs in a given situation, as it might 
be expected. 



5 Comparison with Previous Proposals 

The most outstanding difference of our proposal with previous works ([8]) is the idea of 
considering subjective situations, that may be perceived in different ways by different 
agents. Technically, this fact implies two differences of our approach with respect to 
others: 

- A situation is described with two functions {% and Ti) for each Agenti. 

Thus, we take into account each agent’s perception of the actual situation, consid- 
ering a subjective description of each state. 

- Two satishability and unsatisfiability relations between situations and formulae (\=i 
and =|i) are also defined for each agent. 

Having a subjective description of each state, it makes sense to consider satishabil- 
ity relations that depend on each agent. 

The rest of the section is devoted to the comparison of our proposal with the two 
approaches to the problem of logical omniscience with which it shares more similar- 
ities: Levesque’s logic of explicit and implicit beliefs ([6]) and Thijsse’s hybrid sieve 
systems ([7]). 
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5.1 Levesque’s Logic of Implicit and Explicit Beliefs 

Levesque uses a language with two modal operators: B for explicit beliefs and L for 
implicit beliefs. These operators are not allowed to be nested in the formulae of the 
language. A structure for explicit and implicit beliefs is debited as a tuple M=(S, B, 
T, F), where S is the set of primitive situations, is a subset of S that represents the 
situations that could be the actual one and T and F are functions from the set of primitive 
propositions into subsets of S. Intuitively, T(P) contains all the situations that support 
the truth of P, whereas F(P) contains the ones that support the falsehood of P. A 
situation s can be partial (if there is a primitive proposition which is neither true nor 
false in s) and/or incoherent (if there is a proposition which is both true and false in s). 
A situation is complete if it is neither partial nor incoherent. A complete situation s is 
compatible with a situation t if s and t agree in all the points in which t is debned. B* is 
the set of all complete situations of S that are compatible with some situation in B. 

The relations \=t and \=p between situations and formulae are debned as follows: 

- M,s \=T P, where P is a primitive proposition, if and only if s e T(P) 

- M,s P, where P is a primitive proposition, if and only if s e F(P) 

- M,s \=T if and only if M,s \=f P 

- M,s ~~P if and only if M,s \=t P 

- M,s \=T {p A ■0) if and only if M,s \=t P and M,s \=t ip 

- M,s |=F (p A Ip) if and only if M,s \=p p or M,s \=f ip 

- M,s \=T Bp if and only if M,t \=t p ^teB 

- M,s Bp if and only if M,s Bp 

- M,s \=T Lp if and only if M,t \=t p ^teB* 

- M,s ^F Bp if and only if M,s Bp 

There are some similarities between our approach and Levesque’s logic of implicit 
and explicit beliefs. However, they are more apparent than real, as shown in this listing: 

- Levesque also considers a satisbability and an unsatisbability relation between sit- 
uations and doxastic formulae. 

However, these relations are not considered for each agent. 

- Levesque also describes each situation with two functions T and T. 

These functions are not indexed by each agent, as our functions are (Levesque con- 
siders an objective description of what is true and what is false in each situation). 
Another important difference is that Levesque’s functions deal with basic proposi- 
tions, and not with formulae as our functions do. 

- Both approaches allow the presence of partial or inconsistent situations. 

However note that, in our case, it is not the (objective) description of the situation 
that is partial or inconsistent, but the subjective perception that an agent may have 
of it. Thus, the notions of partiality and inconsistency have a much more natural 
interpretation in our framework. 

- Both approaches avoid all the forms of logical omniscience. 

The reason is different in each case, though. In Levesque’s logic of explicit and 
implicit beliefs, it is the presence of incoherent situations that prevents logical om- 
niscience. In our proposal, there is no need to have inconsistent situations to avoid 
logical omniscience. In fact, we solve that problem by debning 7) and F) over 
arbitrary sets of formulae, and not over basic propositions. 
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- There are accessibility relations between situations for each agent in both systems. 
Levesque’s accessibility relation between situations is left implicit; our accessibil- 
ity relations are explicit. Furthermore, the intuition underlying these relations is 
somewhat different, as explained in section 2. 

Other differences with Levesque’s approach are: 

- Levesque only considers one agent, and does not allow nested beliefs. Thus, his 
agents do not have any introspective capabilities. 

- Levesque defines explicit and implicit beliefs, whereas we do not make this distinc- 
tion. 

- Even though Levesque avoids logical omniscience, his agents must necessarily 
believe all those tautologies that are formed by known basic propositions (those 
propositions P for which the agent believes (P V ^P)), regardless of their com- 
plexity. This is not the case in our approach, because we deal directly with formulae. 

- There is a different treatment of the unsatisfiability relation when applied to beliefs, 
because he transforms =| into whereas we do not. 

5.2 Thijsse’s Hybrid Sieve Systems 

Thijsse ([7]) proposes a way of using partial logics to deal with various forms of logical 
omniscience. He defines a partial model as a tuple (W, Bi, . . . , Bn,V), where LL is a set 
of worlds, Bi is the accessibility relation between worlds for Agenti and U is a partial 
truth assignment to the basic propositions in each world. T is a primitive proposition 
that is always interpreted as true. Truth (|=) and falsity (=|) relations are defined in fhe 
following way: 

_ M,w h T 

- M,Wy^ T 

- M,w\= P, where P is a primitive proposition, iff V {P, w)= 1 

- M,w=\ P, where P is a primitive proposition, iff V (P, w)=0 

- M,w 1= —>(p iff M,w =\ ip 

- M,w =1 iff M,w 1= If 

- M,w \= {p iff M,w 1= p and M,w |= ip 

- M,w =\ {p Aip) iff M,w ^ p or M,w =\ ip 

- M,w\= Bip iff M,v \= p^v such that (w, v) eBi 

- M,w=\ Bip iff s.t. (w, v) eBi and M,v=\ p 

The most important similarities between our approach and Thijsse’s are: 

- n agents and n explicit accessibility relations are considered. 

However, as in Levesque’s case, there are no restrictions on these relations, and the 
intuitive meaning of our accessibility relations is slightly different. 

- Two relations (of satisfiability and unsatisfiability) are defined. Moreover, a similar 
clause is used to provide a meaning to the unsatisfiability relation with respect to 
the belief operator. 

As before, the main difference is that we provide two relations for each agent. 
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- There are no tautologies in Thijsse’s system; therefore, he does not have to care 
about some forms of logical omniscience (closure under valid implication and be- 
lief of valid formulae). 

- Closure under material implication and closure under conjunction do not hold in 
Thijsse’s approach either. 

The main difference with Thijsse’s proposal is that he uses partial assignments of 
truth values over basic propositions for each state; thus, a proposition may be true, false 
or undefined in each state. We deal with formulae, not with basic propositions, and 
each formula may be supported and/or rejected by each agent in each state. Therefore, 
Thijsse’s approach is three-valued, whereas ours is more of a four-valued kind, such as 
Levesque’s. 

6 Summary 

In this paper it has been argued that each agent perceives its actual situation in a partic- 
ular way, which may be different from that of other agents located in the same situation. 
The vision that an agent has of a situation determines its (positive and negative) beliefs 
in that situation. This intuitive idea has been formalized with the notion of subjective 
situations. These entities are the base of a doxastic logic, in which the meaning of the 
belief operators seems to fit with the general intuitions about how the doxastic attitude 
of a non-ideal agent should behave. In particular, logical omniscience is avoided while 
some interesting introspective properties are maintained. A detailed comparison of this 
approach with Levesque’s logic of implicit and explicit beliefs ([6]) and Thijsse’s hy- 
brid sieve systems ([7]) has also been provided. 
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Abstract. We present a formalism for reasoning about the information 
properties of multi-agent systems. Multi-agent VSK, logic allows us to 
represent what is objectively true of some environment, what is visible, 
or aceessible of the environment to individual agents, what these agents 
actually pereeive, and finally, what the agents actually know about the 
environment. The semantics of the logic are given in terms of a general 
model of multi-agent systems, closely related to the interpreted systems 
of epistemic logic. After introducing the logic and establishing its rela- 
tionship to the formal model of multi-agent systems, we systematically 
investigate a number of possible interaction axioms, and characterise 
these axioms in terms of the properties of agents that they correspond 
to. Finally, we illustrate the use of the logic through a case study, and 
discuss issues for future work. 



1 Introduction 

Consider the following scenario: 

A number of autonomous mobile robots are working in a factory, col- 
lecting and moving various goods around. All robots are equipped with 
sonars, which enable them to detect obstacles. To ensure that potentially 
costly collisions are avoided, a number of crash-avoidance techniques are 
used. First, all robots adhere to a convention that, if they detect a poten- 
tial collision, they must take evasive action either when they detect that 
other agents have right of way or when they know that regardless of the 
convention of the right of way this is the only way to avoid a collision. 
Second, a “supervisor” agent C is installed in the factory, which moni- 
tors all data feeds from sonars. In the event of an impending collision, 
this agent is able to step in and override the control systems of indi- 
vidual agents. At some time, two robots, A and B, are moving towards 
each other in a narrow corridor; robot A has the right of way. Robot R’s 
sonar is faulty, and as a result, B fails to notice the potential collision 
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and does not give way to robot A. Robot A, using its sonar, detects the 
presence of robot B. Robot A recognises that B has not taken evasive 
action when it should have done, and reasons that B must be faulty; 
as a consequence, it takes additional evasive action. Meanwhile, the su- 
pervisor agent C, observing the scenario, also deduces that B must be 
faulty, and as a consequence shuts B down. 



The aim of this scenario is not to suggest an architecture for multi-agent robotics, 
but to illustrate the utility of reasoning about the information that agents can 
and do perceive, their knowledge about their environment, and the actions that 
they perform. We argue that the ability to perform such reasoning will be of 
great value if autonomous agents are to be successfully deployed. 

In this paper, we develop a formalism that will allow us to represent and 
reason about such aspects of multi-agent systems. We present multi-agent VSJC 
logic, a multi-agent extension of VSK. logic [9] . This logic allows us to represent 
what is objectively true of an environment, what is visible, or knowable about 
the environment to individual agents within it, what agents perceive of their 
environment, and finally, what agents actually know about their environment. 
Syntactically, VSK logic is a propositional multi-modal logic, containing three 
sets of indexed unary modal operators “Vi”, “5i”, and “/Ci”, one for each agent 
i. A formula Vitp means that the information tp is accessible to agent z; Sitp 
means that agent i perceives information tp; and Kitp means that agent i knows 

ip. 

An important feature of multi-agent VSK logic is that its semantics are given 
with respect to a general model of agents and their environments. We are able 
to characterise possible axioms of multi-agent VSK logic with respect to this 
semantic model. Consider, for example, the VSK formula Viip SjViip, which 
says that if information ip is accessible to agent i, then agent j sees (perceives) 
that if is accessible to i. Intuitively, this formula says that agent j is able to see at 
least as much as agent z; we are able to show this formally by proving correspon- 
dence results with respect to a semantic description of agents and environments, 
as well as the Kripke frames they generate. 

The remainder of this paper is structured as follows. We begin in section 2 
by introducing the semantic framework that underpins multi-agent VSK logic. 
We then formally introduce the syntax and semantics of VSK logic in section 3, 
and in particular, we show how the semantics of the logic relate to the formal 
model of multi-agent systems introduced in section 2. In section 4, we discuss and 
formally characterise various interaction axioms of VSK logic. In section 5, we 
return to the case study presented above, and show how we can use multi-agent 
VSK logic to capture and reason about 

Finally, in section 6, we present some conclusions. 
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2 A Semantic Framework 

In this section, we present a semantic model of agents and the environments 
they occupy. This model plays the role in VSK. logic that interpreted systems 
play in epistemic logic [2, ppl03-107]. 

A multi-agent VSK system is assumed to be comprised of a collection Agi, 

. . . , Ag„ of agents, together with an environment. We formally define environ- 
ments below, but for the moment, it is assumed that an environment can be 
in any of a set E of instantaneous states. We adopt a quite general model of 
agents, which makes only a minimal commitment to an agent’s internal archi- 
tecture. One important assumption we do make is that agents have an internal 
state, although we make no assumptions with respect to the actual structure of 
this state. Agents are assumed to be composed of three functional components: 
some sensor apparatus, an action selection function, and a next-state function. 

Formally, an agent Agi is a tuple Agi = {Li, AcU, seei, doi,Ti, b), where: 

— Li = {ll , if ,...} is a set of instantaneous local states for agent i. 

— Acti = {a],af , . . .} is a set of actions for agent i. 

— seCi : 2^ Perci is the perception function for agent i, mapping sets of 
environment states {visibility sets) to percepts for agent i. 

Elements of the set PerCi will be denoted by p\,pl,. . . and so on. If seCi is 
an injection into PerCi then we say that seCi is perfect, otherwise we say it 
is lossy. 

— doi : Li Acti is the action selection function for agent i, mapping local 
states to actions available to agent i. 

— Ti : Li X PerCi Li is the state transformer function for agent i. 

We say Ti is complete if for any 

g = {e,Ti{li, pi), . . . ,Tn{ln: Pn ) ) 

and 

9 ( In 5 Pn ) ) 

we have that 

n{k,pf) =n{l{,p'i) implies p^ = p)■ 

We say Ti is local if for any 

g = {e,Ti{li, pi), . . . ,Tn{ln: Pn ) ) 

and 

g' = {e' ,Ti{l[, p[), . . . ,Tn{ln, p'n)) 

we have that 

Ti{li, Pi) = Ti{f, Pi) . 

We say that an agent has perfect recall if the function Ti is an injection. 

— b G L is the initial state for agent i. 
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Perfect perception functions distinguish between all visibility sets; lossy percep- 
tion functions are so called because they can map different visibility sets to the 
same percept, thereby losing information. We say that an agent has perfect re- 
call of its history if it changes its local state at every tick of the clock (cf. [2, 
ppl28-131]). 

Following [2], we use the term “environment” to denote all the components 
of a system external to the agents that occupy it. Sometimes, environments can 
be represented as just another agent of the system; more often they serve a 
special purpose, as they can be used to model communication architectures, etc. 
We model an environment as a tuple containing a set of possible instantaneous 
states, a visibility function for each agent, which characterises the information 
available to an agent in every environment state, a state transformer function, 
which characterises the effects that an agent’s actions have on the environment, 
and, finally, an initial state. 

Formally, an environment Env is a tuple 

Env = {E, visi , . . . , visn, Tg, cq) 



where: 

— E = {ei, C 2 , ■ . .} is a set of instantaneous local states for the environment. 

— viSi : E ^ 2^ is the visibility function of agent i. It is assumed that viSi 
partitions E into mutually disjoint sets and that e G visi(e), for any e € E. 
Elements of the codomain of the function vis are called visibility sets. We 
say that viSi is transparent if for any e G E we have that visi{e) = {e}. 

— Te : E X Acti X • • • X Actn ^ 2'®' is a total state transformer function for 
the environment (cf. [2, pl54]), which maps environment states and tuples 
of actions, one for each agent, to the set of environment states that could 
result from the performance of these actions in this state. 

— cq G E is the initial state of Env. 

Modelling an environment in terms of a set of states and a state transformer 
is quite conventional (see, e.g., [2]). The use of the visibility function, however, 
requires some explanation. Before we do this, let us define the concept of global 
state. The global states G = {g, g' , . . .} of a VSJC system are a subset of E x 

Li X • • • X L„. 

The visibility function defines what is in principle knowable about a VSK, 
system; the idea is similar to the notion of “partial observability” in pomdps [6] . 
Intuitively, not all the information in an environment state is in general acces- 
sible to an agent. So, in a global state g = {e,l\,. . . , In), visi(e) = {e, e' , e"} 
represents the fact that the environment states e, e', e" are indistinguishable to 
agent i from e. This is so regardless of agent z’s efforts in performing the obser- 
vation — it represents the maximum amount of information that is in principle 
available to i when observing state e. The concept of transparency, as defined 
above, captures “perfect” scenarios, in which all the information in a state is 
accessible to an agent. Note that visibility functions are not intended to capture 
the everyday notion of visibility as in “object x is visible to the agent” . 
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A multi-agent VSK. system is a structure S = {Env, Agi, . . . , Agn), where 
Env is an environment, and Agi , . . . , Ag„ are agents. The class of VSK. systems 
is denoted by S. 

Although the logics we discuss in this paper may be used to refer to static 
properties of knowledge, visibility, and perception, the semantic model natu- 
rally allows us to account for the temporal evolution of a VSK system. The 
behaviour of a VSK system can be summarised as follows. Each agent i starts 
in state b, the environment starts in state cq. At this point every agent i “syn- 
chronises” with the environment by performing an initial observation through 
the visibility function visi, and generates a percept = seei(viSi(eo)). The 
internal state of the agent is then updated, and becomes n(li,p°). The synchro- 
nisation phase is now over and the system starts its run from the initial state 
ffo = (eo,Ti(li,p?), . . . ,T„(l„,p°)). An action a° = do{Ti{U,p°)) is selected and 
performed by each agent i on the environment, whose state is updated into 
6i = Te(eo, a?, . . . , )• Each agent enters another cycle, and so on. 

A run of a system is thus a (possibly infinite) sequence of global states. A 
sequence {go, gi, g2, ■ ■ .) over G represents a run of a system {Env, Agi, . . . , Agn) 
iff 



-90 = {eo,Ti{li,seei{visi{eo))) 5 ■ ■ ■ 5 '^nO-m see„{viSn{eo)))), and 
- for all u, if gu = (e, h,.. K) and gu+i = {e', l{, ■ ■ ■ , l'„) then: 

e' G Te{cu,ai, .. ., an) and 
I'i = n{k, seei{visi{e'))) 



where = doi{li). 

Given a multi-agent VSK system S = {Env, Agi, . . . ,Agn), we say Gs G G 
is the set of global states generated by 5 if 5 G Gg occurs in a run of S. 

3 Multi-agent VSK Logic 

We now introduce a language C , which will enable us to represent the information 
properties of multi-agent VSK systems. In particular, it will allow us to represent 
first what is true of the VSK system, then what is visible, or knowable of the 
system to the agents within it, then what these agents perceive of the system, and 
finally, what each agent knows of the system. £ is a propositional multi-modal 
language, containing three sets of indexed unary modal operators, for visibility, 
perception, and knowledge respectively. Given a set P of propositional atoms, 
the language C of VSK logic is defined by the following BNF grammar: 

{ag) ::= 1 I •• • I n 

{wff) ::= true | any element of P \ ^{wff) \ {wff) A {wff) 

I V{ag){wff) I Si^ag){wff) \ K(^ag){wff) 

The modal operator “Vi” will allow us to represent the information that is 
instantaneously visible or knowable about the state of the system to agent i. Thus 
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suppose the formula Vi^p is true in some state g € G. The intended interpretation 
of this formula is that the property ip is accessible to agent i when the system 
is in state g. This means that not only p is true of the environment, but agent 
i, if it was equipped with suitable sensor apparatus, would be able to perceive 
p. If -^Vip were true in some state, then no matter how good agent z’s sensor 
apparatus was, it would be unable to perceive p. 

The fact that something is visible to an agent does not mean that the agent 
actually sees it. What an agent does see is determined by its sensors. The modal 
operator “5i” will be used to represent the information that agent i “sees”. The 
idea is as follows. Suppose agent i’s sensory apparatus (represented by the seei 
function in our semantic model) is a video camera, and so the percepts being 
received by agent i take the form of a video feed. Then Sip means that an 
impartial observer would say that the video feed currently being supplied by 
i’s video camera carried the information p — in other words, p is true in all 
situations where i received the same video feed. 

Finally, we can represent the knowledge possessed by agents within a system. 
We represent agent z’s knowledge by means of a modal operator “/Ci”. In line 
with the tradition that started with Hintikka [4], we write JCip to represent the 
fact that agent i has knowledge of the formula represented by p. Our model of 
knowledge is that popularised by Halpern and colleagues [2]: agent i is said to 
know p when in local state I if p is guaranteed to be true whenever i is in state 
1. As with visibility and perception, knowledge is an external notion — an agent 
is said to know p if an impartial, omniscient observer would say that the agent’s 
state carried the information p. 

We now proceed to interpret our formal language. We do so with respect to 
the equivalence Kripke frames generated (see [2]) by VSK. systems. Given a VSK 
system S = {Env, Agi, . . . , Ag„), the Kripke frame 



Fs 



(W, 



1/ S 
? ~l5 



k 



ly s k\ 
'^n 5 '^n ? ^n/ 



generated by S is defined as follows: 

— W=Gs (recall that Gs is the set of global states reachable by system S), 

— For every i = l, . . . ,n, the relation WxW is defined by: (e, Zi, . . . , Z„) 
{e',l[,...,Q if e' G vis^{e), 

— For every i = l, . . . ,n, the relation WxW is defined by: (e, Zi, . . . , Z„) 

(e', l[,. ..,1'^) if see^(vis^(e)) = seei(visi(e')), 

— For every i = l, . . . ,n, the relation C WxW is defined by: (e, Zi, . . . , Z„) 

(e',z(,...,z;) ifk=i'. 

The class of frames generated by a VSK system S will be denoted by tFs- As 
might be expected, all frames generated by systems in S are equivalence frames. 

Lemma 1. Every frame F G iFs is an equivalence frame, i.e., all the relations 
in F are equivalence relations. 

We have now built a bridge between VSK systems and Kripke frames. In what 
follows, we assume the standard definitions of satisfaction and validity for Kripke 
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Axiom 


VSK Class 


Vip ^ p 


none (valid in all systems) 


p => Vip 


visi is transparent 


Sip => Vip 


none (valid in all systems) 


Vip => Sip 


seei is perfect 


K i p SiP 


Ti has perfect recall 


SiP K.iP 


Ti is local 



Table 1. Single-agent interaction axioms in VSK. logic. 



frames and Kripke models — we refer the reader to [5,3] for a detailed exposition 
of the subject. Following [2] and [7], we define the concepts of truth and validity 
on Kripke models that are generated by VSK. systems. 

Given an interpretation tt : W ^ 2^, we say that a formula (p & C is 
satisfied at a point 5 G G on a VSK system S if the model Ms = {Fs,tt) built 
on the generated frame Fs by use of tt is such that Ms \=g p. The propositional 
connectives are assumed to be interpreted as usual, and the modal operators Vi, 
Si, and Ki are assumed to be interpreted in the standard way (see for example 
[5]) by means of the equivalence relations ^i, ~f, and respectively. 

We are especially interested in the properties of a VSK system as a whole. 
The notion of validity is appropriate for this analysis. A formula p € C is valid 
on a class S of VSK systems if for any system S G S, we have that Fs ^ p. 

4 Interaction Axioms in Multi-agent VSK. Logic 

In this section we will study some basic interaction axioms that can be specified 
within VSK logic. Interaction axioms are formulas in which different modalities 
are present; they specify a form of “binding” between the attitudes corresponding 
to the modal operators. 

Note that, in previous work, we have studied and given semantic character- 
isations for single-agent interaction axioms (i.e., axioms in a VSK logic where 
there is only one V operator, only one S operator, and only one K operator) [9]. 
For example, we were able to show that the axiom schema Vp Sp charac- 
terised a particular property of an agent’s perception function: namely, that it 
was perfect, in the sense that we defined in section 2. We summarise these results 
in table 1 . 

In this paper we analyse some multi-agent interaction axioms. The most 
obvious form that these interaction axioms may have is the following: 

u\p=pu^.p where □) G {5i, Vi, G {5j,Vj,/Cj}. (1) 

If we assume i ^ j (the case i = j was dealt with in [9]), Axiom (1) generates 
nine possible interaction axioms in total, as summarised in table 2. The second 
column of table 1 gives the conditions on Kripke models that correspond (in the 
sense of [1]) to the axiom. The third column gives the first-order condition on 
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Axiom 


Kripke 

Condition 


VSK 

Condition 


Vip => Vjp 


V r~ 


1/ 


visj(e) C visi(e) 


Vip => Sjp 


■s r~ 


V 


svj(e) = svj(e') —> visi(e) = visi(e') 


Vip => Kjp 




u 

i 


Ij = Ij —> visi(e) = visi(e') 


Sip => Vjp 




s 

i 


visj(e) = visj(e') svi(e) = svi(e') 


Sip => Sjp 




s 


svj{e) = svj(e') svi{e) = svi(e') 


Sip => Kjp 




s 

'^i 


Ij = Ij svi{e) = svi(e') 


Kip => Vjp 


^ r~ 




II 

T 

II 


Kip ^ Sjp 


s r~ 


^k 
'' i 


svj(e) = svi(e') ^ k = 1- 


Kip ^ Kjp 


k f- 

r^.(Zr 


k 

'~'i 


1— 1' ^ I — !' 



Table 2. Some multi-agent interaction axioms in multi-agent VSK. logic. Note 
that in the table the function svi : E —>■ Perci stands for seci o visi. 



VSK systems that corresponds to the interaction axioms. (Note that in these 
conditions each variable is assumed to be universally quantified: for example, 
the third axiom Vi^p ^ Kjp corresponds to systems S in which for all g = 
. . . ,ln) and g' = {e' ,l{, . . . , l'„), we have that Ij = Zj implies visi(e) = 
visi(e').) 

We begin our analysis with the schema which says that if p is visible to i, 
then (p is visible to j . 

ViP Vjp ( 2 ) 

This axiom says that everything visible to i is also visible to j. Note that the 
first-order condition corresponding to Axiom 2 implies that at least as much 
information is accessible to agent j as agent i. 



ViP ^ Sjp (3) 

Axiom (3) says that j sees everything visible to i. It is easy to see that in 
systems that validate this schema, since j sees everything i sees, it must be that 
everything visible to i is also visible to j. In other words, VSK systems that 
validate Axiom (3) will also validate (2). 



ViP ^ Kjp (4) 

Axiom (4) says that everything visible to i is known to j . 

SiP V? 7^ (^) 

Axiom (5) says that everything i sees is visible to j. Intuitively, this means that 
the percepts i receives are part of the environment that is visible to j . 



Sip Sjp 



(6) 
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Axiom (6) says that j sees everything i sees. Since we know from [9] that any 
system S validates the axiom Sjcp ^ it follows that any VSK. system 

validating Axiom (6) will also validate Axiom (5). Note that from table 2, it 
follows that 



\seej{viSj{E))\ < \seei{viSi{E))\ 

So, since agent i has more perception states at its disposal than agent j, it has 
a finer grain of perception. 



Si<^ => ICjifi (7) 

Axiom (7) says that if i sees tp then j knows tp; in other words, j knows everything 
that i sees. 



ICiif ^ Vj(f ( 8 ) 

Axiom (8) says that if i knows <p, then tp is visible to j. Intuitively, this means 
that i’s local state is visible to j. Axiom (8) thus says that entity j has “read 
access” to the state of another entity i. 



Kip) =5> Sjp (9) 

Axiom (9) captures a more general case than that of (8), where entity j not only 
has read access to the state of i, but that it actually does read this state. Note 
that any system that validates (9) will also validate (8). 



JCiP ICjp (10) 

This final schema says that j knows everything that i knows. Note that from 
the corresponding condition on VSK. systems in table 2, it follows that 

\Lj\<\L.\ 

So, since agent i has more local states, it has a finer grain of knowledge than 
agent j. If we also have the converse of (10), then we would have Kip Kjp 
as valid; an obvious interpretation of this schema would be that i and j had the 
same state. 

All these considerations lead us to the following: 

Theorem 1. For any axiom ip of table 2 and any VSK system S we have that 
the following are equivalent: 

1. The system S validates ip, i.e., 5 1= ip; 

2. The generated frame Fs satisfies the corresponding Kripke condition R.,p; 

3. The system S satisfies the corresponding VSK condition 5,/,. 
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Axiom 


Kripke 

Condition 


VSK 

Condition 


Viip => VjViip 


^ r~ 


1/ 


visj(e) C visi(e) 


Viip => SjViip 


•s r~ 




svj{e) = svj(e') visi(e) = visi(e') 


Viip => KjViip 




1/ 


II 

T 

II 


Siq^ VjSiq^ 




s 


visj(e) = visj(e') svi(e) = svi(e') 


Siifi SjSip 




s 


svj{e) = svj(e') svi(e) = svi(e') 


Si ip — ‘f’ hHj Si ip 




s 

'^i 


Ij = Ij svi{e) = svi(e') 


K.iP — r" V jK.iP 


^ r~ 


i 


visj(e) = visj(e') —> k = 1' 


hUi p — S y Af j p 


s r~ 


^k 


svj{e) = svi(e') ^ h = 1' 


Kip KjKip 


k 

~j(Zr 


k 


I- — 1' ^ I — /' 



Table 3. Other interaction axioms in multi-agent VSK logic. 



Proof ( Outline.). Given any axiom ip in table 2, it is a known result that Fs \= 
if and only if Fs has the Kripke property R^p shown in table 2 (see [7] for details). 
But since validity on a VSK system S is defined in terms of the generated frame 
Fs, the equivalence between items 1 and 2 follows. 

For each line of the table, the equivalence between 2 and 3 can be established 
by re-writing the relational properties on Kripke frames in terms of the VSK 
conditions on VSK systems. 



Other Interaction Axioms Before we leave our study of VSK interaction 
axioms, it is worth noting that there are many other possible interaction axioms 
of interest [7] . The most important of these have the following general form. 

where a] G {S^,V^,K^},a‘^ G {Sj,Vj,Kj},i j. (11) 

It is easy to see that schema (11) generates nine possible interaction axioms. We 
can prove the following general result about such interaction axioms. 

Lemma 2. For any system S, we have that the generated frame Fs satisfies the 
following property. 

Fs h ^Ip => ^j^Ip if and only if 

where □) G {Si,Vi,Ki},uj G {Sj,Vj,Kj} and (respectively ) is the 
equivalence relation corresponding to the modal operator □) (respectively 

Proof. Follows from the results presented in [7, Lemma A. 11]. 

Thanks to the above result we can prove that the classes of VSK systems anal- 
ysed above are also characterised by the axioms discussed in this section. Indeed 
we have the following. 




310 Michael Wooldridge and Alessio Lomuscio 



Corollary 1. For any axiom ip of table 3 and any VSK. system S we have that 
the following are equivalent: 

1. The system S validates ip, i.e., 5 |= ip; 

2. The generated frame Fs satisfies the corresponding Kripke condition R,p; 

3. The system S satisfies the corresponding VSK. condition 5'^. 

Proof. Follows from Lemma 2 and Theorem 1. 

5 A Case Study 

In order to illustrate the use of multi-agent VSK logic, we consider again the 
scenario presented in section 1. While the scenario can be equally explored by 
means of VSK semantics, here we focus on the axiomatic side of the formalism. 

As discussed in section 1, we have three robotic agents A, B, C involved in 
a coordination problem in a navigation scenario. We suppose the autonomous 
robots A, B to be equipped with sonars that can perfectly perceive the envi- 
ronment, up to a certain distance of, say, 1 metre; so their visibiliy function is 
not transparent (see Table 1). We further admit that within 1 metre of distance 
of the object the pairing sonar/environment is perfect; hence within this dis- 
tance the environment is fully visible. For the ease with which we assume it is 
possible to process signals from sensors, we further assume that if the sensors 
are adequately working, then the agents have perfect perception, i.e. they are 
semantically described by a perfect see function as in Table 1. We also assume 
that agents know everything they see, i.e. that their r function is local. 

Further assume that the robots A, B follow the following rule: if they know 
that there is a moving object apparently about to collide with them, then they 
must take evasive action either when this is the only way to avoid a collision, or 
in case the object is another robot, when this has right of way. This rules are 
commonly known, or at least that they hold however nested in a number of K 
operators. The superuser has access to the sensors of all the agents (it therefore 
sees what the agents see and knows what is visible to the agents — see previous 
section) plus some fixed sensors in the environment they inhabit. Hence we model 
agent C by supposing that it has perfect perception of the environment, that 
the environment is completely visible to it and that all its perceptions are known 
by it. 

We can now tailor the specification above to the scenario currently in analysis. 
We have that agents A, B are in a collision course with A having right of way, 
that this is visible both to agent B and to agent A, except that while agent A 
does see this, agent B does not. Formally: 

h coll A VacoU a VbcoU A ^SbcoU A r-o-WA- 

Given the assumptions on the agents presented above, it is possible to show 
that it follows that agent A will take evasive action and that agent B will be 
shut down by the controller agent C . A proof of this is as follows: 
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1. VbcoU A ^SbcoU AVacoU A r-o-WA 

2. VcO^bcoU A ^SbcoU) ^ Sc(VbcoUA 
~^SbcoU) =a ICc{VbcoII A ^SbcoU) 

3. K.c{VbcoII a ^SbcoU) ^ shutdownB 

4. (VbcoU a ^SbcoU) =a- ICc(VbcoU A ^SbcoU) 

5. shutdownB 

6. K.A{{~^ev-actB A t-o-wa) ^ ^ICbcoU) 

7. -^ev-actB ^ SA^ev-actB JCA^ev-acts 

8. ICa^K^b coll 

9. K.a{coU a ^ICb coll) ^ ev-actA 

10. VacoU =a SacoU ICacoU 

11 . ICat-o-wa 

12. ev-actA 



[Given] 

[Perfect Perception] 
[Given] 

[Given] 

[1,3,4 -I- Taut] 

[Given -|- Taut] 
[Perfect Perception] 

[6, 7, K] 

[Given] 

[Perfect Perception] 

[1, Perfect Perception] 
[1, 8, 9, 10, 11, K] 



6 Conclusions 

In order to design or understand the behaviour of many multi-agent systems, it 
is necessary to reason about the information properties of the system — what 
information the agents within it have access to, what they actually perceive, and 
what they know. In this paper, we have presented a logic for reasoning about 
such properties, demonstrated the relationship of this logic to an abstract general 
model of multi-agent systems, and investigated various interaction axioms of the 
logic. Many issues suggest themselves as candidates for future work: chief among 
them is completeness. In [8], we proved completeness for a mono- modal fragment 
of VSIC logic. In particular, we proved completeness not simply with respect to 
an abstract class of Kripke frames, but with respect to the class of Kripke frames 
corresponding to our model of agents and environments. It is reasonable to expect 
the proof to transfer to multi-agent settings. However, when interaction axioms 
of the form studied in section 4 are present, matters naturally become more 
complicated, and an analysis for each different system is required. This is future 
work, as are such issues as temporal extensions to the logic, and complexity 
results. 
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Abstract. We present new tractable cases for default reasoning from conditional 
knowledge bases. In detail, we introduce q-Horn conditional knowledge bases, 
which allow for a limited use of disjunction. We show that previous tractability re- 
sults for e-entailment, proper e-entailment, and 2 - and 2 ^-entailment in the Horn 
case can be extended to the q-Horn case. Moreover, we present feedback-free- 
Horn conditional knowledge bases, which constitute a new, meaningful class of 
conditional knowledge bases. We show that the maximum entropy approach and 
lexicographic entailment are tractable in the feedback-free-Horn case. Our results 
complement and extend previous results, and contribute in refining the tractabil- 
ity/intractability frontier of default reasoning from conditional knowledge bases. 



1 Introduction 

A conditional knowledge base consists of a collection of strict statements in classical 
logic and a collection of defeasible rules (also called defaults). The former are state- 
ments that must always hold, while the latter are rules (j) ^ ip that read as “generally, 
if (p then ip.” For example, the knowledge “penguins are birds” and “penguins do not 
fly” can be represented by strict sentences, while the knowledge “birds fly” should be 
expressed by a defeasible rule (since penguins are birds that do not fly). 

The semantics of a conditional knowledge base KB is given by the set of all de- 
faults that are plausible consequences of KB. The literature contains several different 
proposals for plausible consequence relations and extensive work on their desired prop- 
erties. The core of these properties are the rationality postulates proposed by Kraus, 
Lehmann, and Magidor [17], which constitute a sound and complete axiom system 
for several classical model-theoretic entailment relations under uncertainty measures 
on worlds. More precisely, they characterize classical model-theoretic entailment under 
preferential structures, infinitesimal probabilities, possibility measures, and world rank- 
ings. Moreover, they characterize an entailment relation based on conditional objects. 
A survey of all these relationships is given in [4]. We will use the notion of £-entailment 
to refer to these equivalent entailment relations. 

Mainly to solve problems with irrelevant information, the notion of rational closure 
as a more adventurous notion of entailment has been introduced by Lehmann [20]. It 
is equivalent to entailment in system Z by Pearl [22] (which is generalized to variable 
strength defaults in system by Goldszmidt and Pearl [15,16]), to the least specific 
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possibility entailment by Benferhat et al. [4], and to a conditional (modal) logic-based 
entailment by Lamarre [18]. Finally, mainly to solve problems with property inheritance 
from classes to exceptional subclasses, the maximum entropy approach was proposed 
by Goldszmidt et al. [13] (and recently generalized to variable strength defaults by 
Bourne and Parsons [7]); lexicographic entailment was introduced by Lehmann [19] 
and Benferhat et al. [3]; and conditional entailment was proposed by Geffner [11,12]. 

However, while the semantic aspects of these formalisms are quite well understood, 
about their computational properties only partial results have been known so far. In 
previous work [9], we were filling some of these gaps by drawing a precise picture of 
the complexity of major formalisms for default reasoning from conditional knowledge 
bases. The main goal of this paper now is to complement this work by finding meaning- 
ful cases in which default reasoning from conditional knowledge bases is tractable. In 
particular, we aim at identifying nontrivial restrictions that can be checked efficiently 
and that guarantee sufficient expressiveness. 

The main contributions of this paper can be summarized as follows: 



• We introduce q-Horn conditional knowledge bases, which enrich in the spirit of [5] 
Horn conditional knowledge bases by allowing limited use of disjunction in both 
strict statements and defeasible rules. For example, a default Saturday hiking's/ 
shopping, which informally expresses that on Saturday, someone is normally out 
for hiking or shopping, can be expressed in a q-Horn KB, but not in a Horn KB. 

• We show that previous tractability results for e-entailment [20, 16], proper e-entail- 
ment [14], and z- and z+-entailment [16] in the Horn case can be extended to the 
q-Horn case. Thus, in all these approaches, tractability is retained under a limited 
use of disjunction. 

• We present feedback-free-Horn conditional knowledge bases, which restrict the 
literal-Horn case (where default rules are Horn-like) by requesting that, roughly 
speaking, default consequents do not fire back into the classical knowledge of KB 
and that the defaults can be grouped into non-interfering clusters of bounded size. 
We give some examples from the literature that underline the importance of the 
feedback-free-Horn case. In particular, we show that taxonomic hierarchies that are 
augmented by default knowledge can be expressed in the feedback-free-Horn case. 

• We show that in the feedback-free-Horn case, default reasoning under z*-entail- 
ment [13], z* -entailment [7], lex-entailment [3], and leXp -entailment [19] is tract- 
able. To our knowledge, no or only limited tractable cases [8] for these notions of 
entailment from conditional knowledge bases have been identified so far. 

• Our tractability results for the feedback-free-Horn case are complemented by our 
proof that without a similar restriction on literal-Horn defaults, all the respective 
semantics remain intractable. In particular, this applies to the 1 -literal-Horn case, 
in which each default is literal-Horn and has at most one atom in its antecedent, 
and the strict knowledge consists of Horn-clauses having at most two literals. 



Note that detailed proofs of all results in this extended abstract are given in [10]. 
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2 Preliminaries 

2.1 Conditional Knowledge Bases 

We assume a set of propositional atoms At = {pi, . . . ,p„} with n>\. We use _L and 
T to denote the propositional constants /a/se and true, respectively. The set of classical 
formulas is the closure of At U {_L,T} under the Boolean operations ^ and A. We 
use {(j> f) and V f) to abbreviate ~'f) and A -•f’), respectively, and 

adopt the usual conventions to eliminate parentheses. A literal is an atom pGAt or 
its negation ^p. A Horn clause is a classical formula where <j) is either T or a 

conjunction of atoms, and is either _L or an atom. A definite Horn clause is a Horn 
clause where ip is an atom. 

A conditional rule (or default) is an expression f ^ ip, where (p and ip are classical 
formulas. A conditional knowledge base is a pair KB = {L, D), where L is a finite set 
of classical formulas and D is a finite set of defaults. Informally, L contains facts and 
rules that are certain, while D contains defeasible rules. In case L = 0, we call KB a 
default knowledge base. A default <p ^ ip is Horn (resp., literal-Horn), if (p is either T 
or a conjunction of atoms, and ip is a conjunction of Horn clauses (resp., ip is a literal). 
A definite literal-Horn default is a literal-Horn default p^ip, where ip is an atom. 

Given a conditional knowledge base KB = (L, D), a strength assignment a on KB 
is a mapping that assigns each dG D an integer ^{d) > 0. A priority assignment on KB 
is a strength assignment tt on KB with {7r((i) | d G D} = {0, 1, . . . , fc} for some fc > 0. 

An interpretation (or world) is a truth assignment I: At ^ {true, false}, which is 
extended to classical formulas as usual. We use Tai to denote the set of all worlds for 
At. The world I satisfies a classical formula <p, or / is a model of p, denoted I \= p, 
iff I{p) = true. I satisfies a default p ^ p, or I is a model of p ^ p, denoted 
I\=p^ p, iff I\=p^p. I satisfies a set K of classical formulas and defaults, 
or / is a model of K, denoted I \= K, iff / satisfies every member of K. The world I 
verifies a default p^p iff I \=pAp. I falsifies a default p ^ p, iff I \= p A ~<p 
(that is, I ^ p ^ p). A set of defaults D tolerates a default d under a set of classical 
formulas L iff Z? U L has a model that verifies d. A set of defaults D is under L in 
conflict with a default p ^ p iff all models of D U L U {(/)} satisfy ~^p. 

A world ranking k is a mapping k: Tai {0, 1, . . . } U joo} such that k{I) = 0 
for at least one world /. It is extended to all classical formulas p as follows. If p is 
satisfiable, then k{P) = min{K(/) | / GIai, I |= P}\ otherwise, k{P) = oo. A world 
ranking k is admissible with a conditional knowledge base (L, D) iff Kp^p) = oo for 
all p G L, and k{P) < oo and k{P A p) < n{p A ~'p) for all defaults p ^ p G D. 
A default ranking a on D maps each dG D to a nonnegative integer. 

2.2 Semantics for Conditional Knowledge Bases 

e-Semantics (Adams [1] and Pearl [21]). We describe the notions of e-consistency, 
e-entailment, and proper e-entailment in terms of world rankings. 

A conditional knowledge base KB is e-consistent iff there exists a world ranking 
that is admissible with KB. It is e-inconsistent iff no such a world ranking exists. 
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A conditional knowledge base KB e-entails a default iff either k{4>) = oo 

or k{ 4> Aip) < k{4> a ~'ip) for all world rankings k admissible with KB. Moreover, KB 
properly e-entails (p ^ ip iff KB £-entails <p ^ ip and KB does not £-entail ^ _L. 

The next theorem is a simple generalization of a result by Adams [1]. 

Theorem 2.1 (essentially [1]). A conditional knowledge base {L, D) £-entails a de- 
fault (p ^ Ip iff the conditional knowledge base {L, D\J {<p ^ e-inconsistent. 

Systems Z and Z+ (Pearl [22] and Goldszmidt and Pearl [15,16]). Entailment 
in system applies to £-consistent conditional knowledge bases KB = {L, D) with 
strength assignment cr on KB. It is linked to a default ranking 2 + and a world ranking 
K+, which are the unique solution of the following system of equations: 



z^{d) = 0 


-{d) -G k'^{P> A Ip) 


(for af \ d = ij> ^ Ip G D) 


(1) 




00 


if 




K+{I) = < 


0 


if 7 1= L U D (for all I G Iai) 


(2) 




1 -f max z^{d) 


otherwise 






deO-. I[^d 






default <p^ 


Ip is z^-entailed by {KB, a) at strength t iff either n~^{(p) = oo 


or 



Kff{(p Alp) -\- T < Kff{(p A -'Ip). 

Entailment in system Z is a special case of entailment in system It applies to 
£-consistent conditional knowledge bases KB. A default (p^ip is z-entailed by KB iff 
(p^ip is z^-entailed by {KB, a) at strength 0, where a(d) = 0 for all d G D. 

Maximum Entropy (Goldszmidt et al. [13] and Bourne and Parsons [7]). The no- 
tion of z*-entailment applies to £-consistent conditional knowledge bases KB = {L, D) 
with positive strength assignment cr. It is defined whenever the following system of 
equations (3) and (4) has a unique solution zp, k* with positive zp: 

fvg (0 A -I'i/)) = cr{(p ^ Ip) k*s{4> a Ip) (for afl d = ^ ip G D) (3) 

{ oo if 

0 ifl\=LyjD gii J ^ (4) 

^ zp{d) otherwise 
d^D ; I^d 



The uniqueness of zp and k* is guaranteed by assuming that k* is robust [7], which is 
the following property: for all distinct defaults d\,d2G D, it holds that all models Ii 
and I 2 of L having smallest ranks in k* such that Ii ^ di and I 2 ^ ^ 2 , respectively, are 
different. That is, di and d 2 do not have a common minimal falsifying model under L. 
We say KB is robust iff the system of equations given by (3) and (4) has a unique 
solution zp, K* such that zp is positive and k* is robust. A default (p^ ip is zp -entailed 
by {KB, a) at strength t iff either k* {(p) = 00 01 K*{(p A ip) -f t < K*{(p A -•ip). 

The notion of z*-entailment is a special case of z* -entailment. It applies to e- 
consistent minimal-core conditional knowledge bases KB = {L, D) without strength 
assignment, where KB is minimal-core iff for each default dG D there exists a model / 
of LU{D — {(i}) that falsifies d. A default (p^ip is z* -entailed by KB iff (p^ip is 
z*-entailed by {KB, a) at strength 1, where a{d) = 1 for all d G D. 
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Lexicographic Entailment (Lehmann [19] and Benferhat et al. [3]). Lexicographic 
entailment in [3] applies to conditional knowledge bases KB = (L, D) with a pri- 
ority assignment tt on KB, which defines an ordered partition {Dg, . . . , Dk) of D 
by Di = {d^D \ Tr{d) = i}, for all i<k. It is used to define a preference ordering 
on worlds as follows. A world I is ir-preferable to a world /' iff there exists some 
i G {0, . . . ,k} such that \{d G Di \ I \= ci}| > |{d G Di \ I' \= d}| and \{d G Dj \ I \= 
(i}| = |{(i G Dj I /' 1= c?}| for all i < j <k. A model / of a set of classical formulas T 
is a TT-preferred model of T iff no model of T is tr-preferable to 1. A default is 

lexp-entailed by {KB, tt ) iff ip is satisfied in every 7r-preferred model of LU{f}. 

The notion of lexicographic entailment in [19] is a special case of lexicographic 
entailment as above. It applies to e-consistent conditional knowledge bases KB, and 
uses the default ranking 2 of KB in system Z as priority assignment. That is, a default 
is lex-entailed by KB iff is leXp-entailed by {KB, z). 

2.3 Example 

Consider the following conditional knowledge base KB = {L, D), adapted from [16], 
which represents the strict knowledge “all penguins are birds”, and the defeasible rules 
“generally, birds fly”, “generally, penguins do not fly”, “generally, birds have wings”, 
“generally, penguins live in the arctic”, and “generally, flying animals are mobile”. 

L = {penguin bird} , 

D = {bird ^ fly, penguin ^ ^fiy, bird swings, penguins arctic, fly ^mobile} . 

We would like KB to entail “generally, birds are mobile” (as birds generally fly, 
and flying animals are generally mobile) and “generally, red birds fly” (as the property 
“red” is not mentioned at all in KB and should thus be considered irrelevant to the 
flying ability of birds). Moreover, KB should entail “generally, penguins have wings” 
(as the set of all penguins is a subclass of the set of all birds, and thus penguins should 
inherit all properties of birds), and “generally, penguins do not fly” (as properties of 
more specific classes should override inherited properties of less specific classes). 

The corresponding behavior of e-, z-, z*-, and lex-entailment is shown in Table 1 . In 
detail, bird mobile is a plausible consequence of KB under all notions of entailment 
except for e-entailment. Moreover, in this example, every notion of entailment except 
for e-entailment ignores irrelevant information, while every notion of entailment except 
for e- and z-entailment shows property inheritance from the class of all birds to the 
exceptional subclass of all penguins. Finally, the default penguin ~^fly is entailed by 
KB under all notions of entailment. 

For instance, let us verify that penguin — > ~^fly is e-entailed by KB. By Theorem 2. 1 , 
we have to check that {L, D U {penguins fly}) is £-inconsistent. But this is indeed 
the case, since there is no world ranking k that satisfies K{penguin) < oo as well as 
K{penguin A ~^fly) < K{penguin A fly) and K{penguin A fly) < K{penguin A ~^fly). 
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Table 1. Plausible consequences of KB under different semantics 





bird —> mobile 


red A bird ^ fly 


penguin wings 


penguin -ifly 


e-entailment 
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2 -entailment 


+ 




- 


+ 


2 * -entailment 
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+ 


lex-entailment 


+ 


+ 


+ 


+ 



3 Overview of Tractability Results 

3.1 Problem Statements 

A default reasoning problem is a pair {KB, d), where KB = {L, D) is a conditional 
knowledge base and d is a default. It is Horn (resp., literal-Horn) iff L is a finite set 
of Horn clauses, D is a finite set of Horn (resp., literal-Horn) defaults, and d is a Horn 
(resp., literal-Horn) default. In case of z~^- and z*-entailment, we assume that KB and 
d have additionally a strength assignment a{KB) and a strength r{d), respectively. In 
case of leXp-entailment, KB has in addition a priority assignment tt{KB). 

Informally, a default reasoning problem represents the input for the entailment prob- 
lem under a hxed semantics S. We tacitly assume that KB satisfies any preconditions 
that the definition of 5-entailment in the previous section may request. 

We consider the following problems: 

• Entailment: Given a default reasoning problem {KB, d), decide whether KB 
entails d under some fixed semantics S. In case of and z* -entailment, decide 
whether d is z+- and z*-entailed, respectively, by {KB, a{KB)) at strength r((i). In 
case of leXp -entailment, we are asked whether d is lexp -entailed by {KB, tt{KB)). 

• Ranking: Given a conditional knowledge base KB, compute the default ranking 
R of KB according to some fixed semantics S (that is, the rank of each d G D). 

• Rank-Entailment: Same as entailment, but the (unique) default ranking R of 
KB according to some fixed semantics S is part of the problem input. 

3.2 Previous Tractability Results 

Previous results on the tractability/intractability frontier can be described as follows. 

Deciding e-entailment is intractable in the general case [20] and tractable in the 
Horn case [20,16]. Similarly, deciding proper £-entailment is intractable in the general 
case [9] and tractable in the Horn case [14]. Moreover, the problems Entailment, 
Ranking, and Rank-Entailment for systems Z and are intractable in the gen- 
eral case [9] and tractable in the Horn case [16]. 

The problems Entailment, Ranking, and Rank-Entailment for the seman- 
tics z* and z* are intractable even in the literal-Horn case [9]. Moreover, also deciding 
lex- and leXp-entailment is intractable in the literal-Horn case [9]. To our knowledge, 
no or only limited tractable cases for these notions of entailment have been identified 
so far (a limited tractable case for leXp-entailment has been presented in [8]). 
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Fig. 1. Tractability of Entailment 
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Fig. 2. Tractability of RANKING and Rank-Entailment 



3.3 New Tractability Results 

It would be interesting to know whether the tractability results for e-entailment, proper 
e-entailment, and z- and 2+ entailment in the Horn case can be extended to more ex- 
pressive classes of problems. Moreover, it would be interesting to know whether there 
are meaningful tractable classes of problems for z*-, z*-, lex-, and leXp -entailment. 

Concerning the first issue, we introduce the class of q-Horn conditional knowledge 
bases. This class generalizes Horn conditional knowledge bases syntactically by allow- 
ing a restricted use of disjunction, and contains instances that cannot be represented in 
Horn conditional knowledge bases. As we show, the tractability results for Horn condi- 
tional knowledge bases extend to q-Horn conditional knowledge bases. 

Finding meaningful tractable cases for the more sophisticated semantics for condi- 
tional knowledge bases is more challenging. A natural attempt is to show that a further 
restriction of the literal-Horn case leads to tractability. An obvious candidate restriction 
is bounding the size of the bodies in the strict and classical rules to at most one atom. 
Unfortunately, this does not buy tractability. An analysis of our proof reveals that the in- 
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teraction of the defaults among each other and with the classical background knowledge 
must be controlled such that interferences have a local effect. This leads us to the class 
of feedback-free-Horn (ff-Horn) default reasoning problems. As we show, tractability 
is gained on this class for all the intractable semantics discussed here. 

The hierarchy of all classes of conditional knowledge bases considered in this paper, 
along with the corresponding tractability results, is given in Figures 1-2. 

4 Q-Horn 

4.1 Motivating Example 

Q-Horn conditional knowledge bases generalize Horn conditional knowledge bases by 
allowing a limited form of disjunction, which is illustrated by the following example. 

Example 4.1. Assume that John is looking for Mary. Unfortunately, he did not find 
her at home. So, he is wondering where she might be. He knows that Mary might have 
tea with her friends, that she might be in the library, or that she might play tennis. He 
also knows that these scenarios are pairwise exclusive and not exhaustive. Moreover, 
John knows that “generally, in the afternoon, Mary is having tea with her friends or 
she is in the library” and that “generally, on Friday afternoon, Mary plays tennis”. This 
knowledge can be expressed by the following KB = (L, D): 

L = {^tea V ^library, ^tea V ^tennis, ^library V -^tennis} , 

D = {afternoon — > tea V library, Friday A afternoon — > tennis} . 

Assume that it is Friday afternoon and that John is wondering whether he should go 
to the library to look for Mary. That is, does KB entail Friday A afternoon library ? 

4.2 Definitions 

A clause is a disjunction of literals. A default is clausal iff f is either T or a 

conjunction of literals, and fiisa. conjunction of clauses. A conditional knowledge base 
KB = {L, D) is clausal iff L is a finite set of clauses and D is a finite set of clausal 
defaults. A default reasoning problem {KB, d) is clausal iff both KB and d are clausal. 

A classical formula f is in conjunctive normal form (or CNF) iff f is either T or a 
conjunction of clauses. We use the operator ~ to map each atom a to its negation ^a, 
and each negated atom ~^a to a. We define a mapping Af that associates each clausal 
default d with a classical formula in CNF as follows. If d is oftheformT ^ ciA- • -Acn 
with clauses ci, . . . , c„, thenA/’(d) = ciA- • -Ac„. If dis of the form Zi A- • -Aim ciA 
• • • A c„ with literals li, . . . ,lm and clauses ci , . . . , c„, then Af{d) is the conjunction of 
all ~ Zi V • • - y ^Ira'A Ci with i G {1, . . . ,n}. We extend JV to classical formulas in CNF 
<j) by Af{4>) = (j). We extend Af to finite sets K of classical formulas in CNF and clausal 
defaults as follows. Let K' denote the set of all fc G AT with Af{k) f T .If K' (/}, then 

Af{K) is the conjunction of all Af{k) with k G K'. Otherwise, Af{K) = T. 

A partial assignment S' is a set of literals such that for every atom a G At at most 
one of the literals a and ~^a is in S. A classical formula in CNF f is q-Horn [5] iff there 
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exists a partial assignment S such that (i) each clause in (j) contains at most two literals 
outside of S, and (ii) if a clause in (j) contains exactly two literals u,v ^ S, then neither 
~ u nor ~ V belongs to S. Note that every conjunction of Horn clauses is q-Horn. 

A finite set K of classical formulas in CNF and clausal defaults is q-Horn iff JV{K) 
is q-Horn. A conditional knowledge base KB = {L, D) is q-Horn iff KB is clausal 
and L U I? is q-Horn. Clearly, every Horn KB is q-Horn, but not vice versa. A default 
reasoning problem {KB, d) is q-Horn, if KB is q-Horn and d is a clausal default. 

Example 4.2. The conditional knowledge base KB = {L, D) of Example 4.1 is q- 
Horn. In detail, the classical formula A/^(L U D) associated with KB is given by: 

Af{L U D) = {-^tea V ^library) A {^tea V -^tennis) A {Hibrary V ^tennis) A 
{^afternoon V tea V library) A {-^Friday V ^afternoon V tennis) . 

A partial assignment that satisfies (i) and (ii) is given by {^Friday, -^afternoon} . That 
is, N{L U D) is q-Horn. Since KB is also clausal, it thus follows that KB is q-Horn. 

Note that KB can be made Horn by “renaming” atoms, in particular, by replacing 
the atom library by a negated new atom library, where library stands for -^library. 
However, if the scenarios were exhaustive and thus the clause library V tea V tennis is 
in KB, then no Horn renaming of KB is possible. But, the resulting KB is still q-Horn. 

The size of a classical formula in CNF (j), denoted ||^|j, is defined as the number 
of occurrences of literals in <j). We use |</)| to denote the number of clauses in (j). The 
size of a clausal default d = 4>^‘ijj, denoted ||d||, is dehned as ||(/)|| -f ||'!/)||. The size of 
a hnite set of clauses L, denoted |1L||, is defined as the size oiM{L). The size of a 
clausal KB = {L, D), denoted |1 is defined as the size of Af{L U D). We use \D\ 
to denote the cardinality of D. 

4.3 Q-Horn Formulas 

The problems of deciding whether a q-Horn formula is satishable and of recognizing 
q-Horn formulas are both tractable and can in fact be solved in linear time. 

Proposition 4.3 (see [5,6]). a) Given a q-Horn formula deciding whether f is sat- 
isfiable can be done in time 0(||(/)||). b) Given a classical formula in CNF f, deciding 
whether f is q-Horn can be done in time 0(||^||). 

By this result, it follows easily that also q-Horn conditional knowledge bases can be 
recognized in linear time. 

Theorem 4.4. Given a clausal conditional knowledge base KB = {L, D), deciding 
whether KB is q-Horn can be done in time 0{\\KB\\). 

4.4 e-Semantics 

The following theorem shows that deciding whether a q-Horn KB is e-consistent is 
tractable. The proof of this result is based on the fact that checking the £-consistency 
of KB is reducible to a polynomial number of classical satisfiability tests. By closure 
properties of q-Horn formulas, it then follows that for q-Horn KB, each satisfiability 
test is done on a q-Horn formula and thus possible in polynomial time. 
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Theorem 4.5. Given a q-Horn conditional knowledge base KB = (L, D), deciding 
whether KB is e-consistent is possible in time 0{\D\'^ ||7Ti?||). 

The next result shows that deciding e-entailment is tractable in the q-Horn case. 

Theorem 4.6. Given a q-Horn default reasoning problem {KB, d) = {{L, D), f ip), 
deciding whether KB e-entails d is possible in time 0((||(/)|| + |i/'|) \D\^ (|| KB 1 1 + 1 1 V' 1 1 ) ) • 

Finally, deciding proper e-entailment is also tractable in the q-Horn case. 

Theorem 4.7. Given a q-Horn default reasoning problem {KB, d) = {{L, D), f ip), 
deciding whether KB properly e-entails d is possible in time 0((||^|| -I- |'0|) \D\'^ 

{\\KB\\ + \\m- 



4.5 Systems Z and Z+ 

We next focus on entailment in systems Z and The following result, which can be 
proved in a similar way as Theorems 4. 5^.7, shows that computing the default ranking 
is tractable in the q-Horn case. Since system properly generalizes system Z, this 
result shows also that computing the default ranking z is tractable in the q-Horn case. 

Theorem 4.8. Given an e-consistent q-Horn conditional knowledge base KB — {L, D) 
with strength assignment a, the default ranking z~^ can be computed in polynomial time. 

Finally, the following theorem shows that deciding z+-entailment is tractable in 
the q-Horn case. Again, since system properly generalizes system Z, this result 
shows also that deciding z-entailment is tractable in the q-Horn case. Trivially, these 
tractability results remain true when z+ and z, respectively, are part of the input, that 
is, for Rank-Entailment. 

Theorem 4.9. Given a q-Horn default reasoning problem {KB, d) = {{L, D), p ip), 
where KB is e-consistent and has a strength assignment a, deciding whether {KB, a) 
-entails d at a given strength r > 0 can be done in polynomial time. 



5 Feedback-Free-Horn 

5.1 Intractability Results for 1 -Literal-Horn Case 

How do we obtain tractability of deciding s-entailment, where s G {z* z*, lex, lexp}? In 
particular, are there any syntactic restrictions on default reasoning problems that give 
tractability? We could, for example, further restrict literal-Horn defaults by limiting 
the number of atoms in the antecedent of each default as follows. A default p^ip 
is 1 -literal-Horn iff p is either T or an atom, and is a literal. A 1-Horn clause is a 
classical formula p^p, where p is either T or an atom, and pis a literal. A conditional 
knowledge base KB = {L, D) is 1 -literal-Horn iff L is a finite set of 1-Horn clauses 
and Z? is a finite set of 1 -literal-Horn defaults. A default reasoning problem {KB, d) is 
1 -literal-Horn iff both KB and d are 1 -literal-Horn. 

Unfortunately, the following theorem shows that deciding z*-entailment is still (pre- 
sumably) intractable even for this very restricted kind of default reasoning problems. 
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Theorem 5.1. Given a 1-literal-Horn KB, which is e-consistent and minimal-core, and 
a 1-literal-Horn default d, deciding whether KB z* -entails d is co-NP-Ztoni. 

Informally, this intractability is due to the fact that the default knowledge generally 
does not fix a unique instantiation of the atoms to truth values, in particular, when 
defaults “fire back” into the bodies of other defaults, and when defaults are logically 
related through their heads. 

Since z*-entailment is a proper generalization of z*-entailment, it immediately fol- 
lows that deciding 2 * -entailment is (presumably) intractable in the 1-literal-Horn case. 



Corollary 5.2. Given a 1-literal-Horn conditional knowledge base KB, which is e- 
consistent and robust, a strength assignment a on KB, a 1-literal-Horn default d, and 
a strength r, deciding whether {KB, a) z* -entails d at strength r is co-NP-hard. 

The following theorem shows that also deciding lex- and leXp-entailment is (pre- 
sumably) intractable in the 1-literal-Horn case. 

Theorem 5.3. a) Given an e-consistent 1-literal-Horn conditional knowledge base KB 
and a 1 -literal-Horn default d, deciding whether KB lex-entails d is co-NP-Ziani. 

b) Given a 1-literal-Horn conditional knowledge base KB with priority assignment tt 
and a 1-literal-Horn default d, deciding whether {KB , tt) lexp-entails d is co-NP-hard. 

5.2 Motivating Examples 

We will see that deciding s-entailment, where s G {z*, z*, lex, lexp}, becomes tractable, 
if we assume that the default reasoning problems can be sensibly decomposed into 
smaller problems of size bounded by a constant. We now give some examples to illus- 
trate the main ideas behind this kind of decomposability. In the following examples, 
we assume that conditional knowledge bases are implicitly associated with a strength 
assignment cr (resp., priority assignment tt), when s = z* (resp., s = lexp). 

Example 5.4. Take again KB = {L, D) of Section 2.3. Assume that we are wondering 
whether KB s-entails penguin -^fiy, red A bird -^fly, bird — > mobile, penguin — > arctic, 
or penguin — > wings, where sG {z*,z*, lex, lexp}. As it turns out, each of these prob- 
lems can be reduced to one classical reasoning problem and one default reasoning prob- 
lem. More precisely, the former is done w.r.t. the set of atoms {penguin, bird, red}, 
which refers to the atoms in L and the antecedent of the query default, while the 
latter is done w.r.t. the sets of atoms {fly, mobile}, {arctic}, and {wings}, respec- 
tively, by sensibly eliminating irrelevant defaults and simplifying the remaining de- 
faults by instantiating atoms to truth values. For instance, deciding whether KB s- 
entails red A bird -^fly is reduced to the classical reasoning problem of computing the 
least model of L U {red A bird} and the default reasoning problem of deciding whether 
{{red, bird, ^penguin}, {bird ^ fly, fly ^mobile}) s-entails red /\ bird ^ fly. 



We next consider a taxonomic hierarchy adorned with some default knowledge [2]. 
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Example 5.5. The strict knowledge “all birds and fish are animals”, “all penguins and 
sparrows are birds”, ”no bird is a fish”, “no penguin is a sparrow”, and the defeasible 
knowledge “generally, animals do not swim”, “generally, fish swims”, and “generally, 
penguins swim” can be represented by the following KB = {L,D): 

L = {bird ^ animal, fish ^ animal, penguin^ bird, 

sparrow bird, bird ~^fish, penguin ^sparrow} , 

D = {animal — > ^swims, fish swims, penguin —>■ swims} . 

Do sparrows generally swim? That is, does KB s-entail sparrow swims, where 
s G {z*, z}, lex, lexp}? This default reasoning problem can be reduced to one classical 
reasoning problem w.r.t. the set of atoms {animal, bird, fish, sparrow, penguin} and 
one default reasoning problem w.r.t. the set of atoms {swims}. In detail, we first com- 
pute the least model of L\J {sparrow} and then decide whether {{sparrow, bird, animal, 
-^fish, ^penguin}, {animals ^swims}) s-entails sparrow ^ swims. 

5.3 Definitions 

Suppose that for a literal-Horn conditional knowledge base KB = {L, D), there exists 
a set of atoms Ata C At such that L is defined over Ata and that all consequents of 
definite literal-Horn defaults in D are defined over At — Ata. The greatest such Ata, 
which clearly exists, is called the activation set of KB. Intuitively, in any “context” 
given by L and fi, where (j) is either T or a conjunction of atoms from At, all those 
atoms in Ata that are not logically entailed by L U {^} can be safely set to false in the 
preferred models of L U {(/>}. 

For Ata, there is a greatest partition {Ati, . . . , Atn} of At — Ata such that every 
dG D is defined over some Ata U Ati with i G {1, . . . ,n}, which we call the default 
partition of KB. We say KB — {L, D) is k-feedback-free-Horn (or k-ff-Horn) iff it is 
literal-Horn, it has an activation set Ata, and it has a default partition {Ati, ■ ■ ■ , Atn} 
such that every Ati with i G {1, . . . ,n} has a cardinality of at most k. 

Example 5.6. The conditional knowledge base KB of Example 5.5 is 1-ff-Horn. More 
precisely, its activation set (resp., default partition) is given by {animal, bird, fish, 
sparrow, penguin} (resp., {{swims}}). 

Moreover, KB of Example 5.4 is 2-ff-Horn. Its activation set (resp., default parti- 
tion) is given by {penguin, bird, red} (resp., {{fiy, mobile}, {arctic}, {wings}}). 

For sets of Horn clauses L, we use to denote the set of all definite Horn clauses 
in L. For sets of literal-Horn defaults D, we use to denote the set of all definite 
literal-Horn defaults in D. Assume additionally that d = (f>^fi’isa. literal-Horn default. 
Then, a literal-Horn default a — > a (resp., a ~^a) with aG At is active w.r.t. {L, D) 
and d iff L+ U U {fi} \= a (resp., L+ U D+ U {(j)} ^ a A a). 

A default reasoning problem {KB, d) = {{L, is k-jf-Hom, where A: > 1, 

iff (i) it is literal-Horn, and (ii) {L, Da U {c?}) has an activation set Ata and a default 
partition {At\, . . . , Atn} such that d is defined over some Ata U Atj with \Atj \ < k, 
where Da is the set of all active defaults in D w.r.t. KB and d. The class k-ff-Horn 
consists of all fc-ff-Horn default reasoning problems; we define the class feedback-free- 
Horn (ov ff-Horn) by ff-Horn = /c-ff-Horn. 
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Example 5.7. Consider the literal-Horn default reasoning problem {KB, d) with KB = 
{L, D) as in Example 5.4 and d = red A bird -^fly. The set Da of active defaults in D 
w.r.t. KB and d is given by Da = {bird -^fly, bird — > wings, fly mobile}. 

Now, (L, Da U {d}) has the activation set Ata = {penguin, bird, red, arctic} and 
the default partition {Ati, At2}, where At\ = {fly, mobile} and At2 = {wings}. More- 
over, d is defined over Ata U Ati with \ Ati \ = 2. That is, {KB, d) is 2-ff-Horn. 

For Horn conditional knowledge bases KB = {L, D) with activation set Ata, and 
classical formulas a that are either T or conjunctions of atoms from At, we define the 
classical formula a* as follows. If L U {a} is satisfiable, then a* is the conjunction of 
all bG At with L U {a} |= b and all ~^b with b G Ata and L U {a} ^ b. Otherwise, 
we define a* = _L. Moreover, for satisfiable L U {a}, we define the world I* over the 
activation set Ata by T„(6) = true iff L U {a} [= b, for all b G Ata. 

5.4 Recognizing Feedback-Free-Horn 

Both recognizing /c-ff-Horn conditional knowledge bases, and computing their activa- 
tion set and default partition are efficiently possible using standard methods. 

Theorem 5.8. a) Given a literal-Horn conditional knowledge base KB and an integer 
k> 1, deciding whether KB is k-jf-Horn can be done in linear time. 

b) Given a k-jf-Horn conditional knowledge base KB, computing the activation set Ata 
and the default partition {Ati, ■ ■ ■ , Atn} can be done in linear time. 

Moreover, recognizing fc-ff-Horn default reasoning problems is also efficiently possible. 



Theorem 5.9. a) Given a literal-Horn default reasoning problem {KB, d), and an in- 
teger k> deciding whether {KB, d) is k-ff-Horn can be done in linear time, 
b) Given a k-ff-Horn default reasoning problem {KB, d) with KB = {L, D), computing 
the set Da of active defaults in D w.r.t. KB and d can be done in linear time. 



5.5 Maximum Entropy Semantics 

In the sequel, let KB = (L, Z?) be an £-consistent fc-ff-Horn conditional knowledge base 
with positive strength assignment a. Let Ata denote the activation set of KB, and let 
{Ati, ... , Atn ) be the default partition of KB . Let z* be a ranking that maps each dGD 
to a positive integer, and let re* be defined by (4). 

For each i G {1, ... ,n}, let Di denote the set of all defaults in D that are defined 
over Ata U Ati. Let the function rc* ^ on worlds I over At be defined as follows: 



<i{I) 



'oo if/jAL 

, 0 A I \= L yj Di 

Zs {d) otherwise. 

. d^Di : I^d 



(5) 



In order to compute the default ranking z*, we have to compute ranks of the form 
K*(a A /3i A • • • A /?„), where a is either T or a conjunction of atoms from Ata, and 




326 



Thomas Eiter and Thomas Lukasiewicz 



each Pi is either T or a conjunction of literals over Ati. It can now be shown that such 
Kg (a A /3i A • • • A Pn) coincide with A)- 

Using this result, it can be shown that computing the default ranking z* is tractable 
in the fc-ff-Horn case. Since z* is a proper generalization of z*, this result shows also 
that computing the default ranking z* is tractable in the fc-ff-Horn case. 

Theorem 5.10. Let k> 0 a fixed integer. Given an e-consistent k-jf-Horn KB = (L, D) 
with positive strength assignment a, computing the default ranking z* for KB. if KB is 
robust, and returning nil otherwise, can be done in polynomial time. 

In the sequel, let {KB, d) = {{L, D) , p ^ p) he a fc-ff-Horn default reasoning prob- 
lem with £-consistent and robust KB. Let cr be a positive strength assignment on KB. 
Let Da be the set of active defaults in D w.r.t. KB and d, let Ata be the activation set 
of (L, Da U {(i}), and let {Ati, . . . , Atn) be the default partition of (L, Da U {d}). Let 
z*, K* be the unique solution of (3) and (4). 

For every i G {1, . . . ,n},let Di denote the set of all defaults in Da that are defined 
over Ata U Ati, and let ai be the restriction of cr to Let zL map each default in Di 
to a positive integer, and let the function on worlds I over At be dehned by: 

{ oo ifl^L 

0 ^ ifl^LuDi ^6) 

(d) Otherwise. 

: I^d 

It can be shown that in order to decide whether KB z*-entails d at given strength 
T > 0, it is sufficient to know all z* {d) with dG Dj, where j G {1, . . . ,n} such that d 
is dehned over Ata U Atj. Moreover, it can be shown that the restriction of z* to Dj 
coincides with the default ranking for {L, Dj) under the strength assignment aj. 

Using these results, it can be shown that deciding z*-entailment is tractable in the 
/c-ff-Horn case. Again, since z* properly generalizes z*, this result shows also that 
deciding z*-entailment is tractable in the fc-ff-Horn case. Trivially, these tractability 
results remain true when z* and z*, respectively, are part of the input. 

Theorem 5.11. Let k > 0 be fixed. Given a k-ff-Horn default reasoning problem 
{KB,d) = {{L, D),p->-p), where KB is e-consistent and robust, and a positive 
strength assignment a on KB, deciding whether {KB, a) z* -entails d at given strength 
T > 0 can be done in polynomial time. 

Example 5.12. Let the 2-ff-Horn default reasoning problem {KB,d) be given by 
KB = {L, D) of Example 5.4 and d = red A bird ^ fly. Let a{5) = 1 for all S G D. 

Now, d is Zg -entailed by {KB, a) at strength r iff either (i) L U {red A bird, -fly} is 
unsatishable, or (ii) both L U {red A bird, fly} and L U {red A bird, -^fly} are satishable, 
and K*{red A bird A fly) -f r < K*{red A bird A -^fly). It can be shown that the latter 
is equivalent to K*i{{red A bird)* A fly) t < K*i{{red A bird)* A -^fly), that is, 
^^^{red A bird A fly) t < K*i{red A bird A ~^fly), where nfi is dehned through the 
default ranking for {L, Di) = {L, {bird -^fly, fly mobile}) under a\ = cr\Di- 
It is now easy to verify that zffldi) = 1 for all di G Di, that both L U {red A 
bird, fly} and L U {red A bird, ~^fly} are satishable, that Kfi{red A bird A fly) = 0, and 
that Kfi{red A bird A ^fly) = 1. Thus, {KB, a) z} -entails red A bird ^ fly at strength 1. 
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5.6 Lexicographic Entailment 

We now focus on lexicographic entailment. In the sequel, let {KB , d) = {{L, D) , <j> ^ ip) 
be a fc-ff-Horn default reasoning problem. Let tt be a priority assignment on KB. Let 
Da denote the set of all active defaults w.r.t. KB and d, let Ata be the activation set of 
(L, Da U {d}), and let {Ati , . . . , Atn) be the default partition of {L, Da U {d}). 

For every i C {1, . . . , n}, let 1?^ denote the set of all defaults in Da that are defined 
over Ata^Ati, and let KBi = {L, Di). Let tt^ be the unique priority assignment on KBi 
that is consistent with tt on KB (that is, Tii{d) < TTi{d) iff 7r(fi) < 7r(fi), for all d C Di). 
Let j G {1, ... ,n} such that d is defined over Ata U Atj . 

In order to decide whether {KB,tt) leXp-entails d, we must check whether every 
TT-preferred model of L U {(j>} satisfies ip. It can now be shown that we can equivalently 
check whether every tTj -preferred model of L U {<p*} satisfies ip. 

Using this result, it can be shown that deciding leXp-entailment is tractable in the 
/c-ff-Horn case. Moreover, as computing the z-partition for e-consistent conditional 
knowledge bases KB is tractable in the Horn case [16], this result shows also that 
deciding lex-entailment is tractable in the /c-ff-Horn case. 

Theorem 5.13. Let k > 0 be fixed. Given a k-jf-Horn default reasoning problem 
{KB,d) = {{L,D),p->-ip) and a priority assignment tt on KB, deciding whether 
{KB, tt) leXp-entails d can be done in linear time. 

Example 5.14. Let the 2-ff-Horn default reasoning problem {KB,d) be given by 
KB = (L, D) of Example 5.4 and d = red A bird ^fiy. Let 7r(<5) = 0, if i5 G {bird ^fiy, 
bird —>■ wings, fly — > mobile}, and 7t(i5) = 1, if (5 G {penguin —>■ ~^fiy, penguin —>■ arctic}. 

It can be shown that {KB, tt) leXp-entails red A bird -^fiy iff either L U {red A bird} 
is unsatisfiable, or all tti - preferred models of L U {{red A bird)*} = L U {red A bird} 
satisfy fly, where tti is the priority assignment on KB\ = {L, D\) = {L, {bird ^ fly, 
fly mobile}) that maps each element of Di to 0. It is now easy to verify that this is 
indeed the case. That is, {KB, tt) leXp-entails red A bird ^ fly. 
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Abstract. We consider the monodic formulas of common knowledge 
predicate logic, which allow applications of epistemic operators to for- 
mulas with at most one free variable. We provide finite axiomatizations 
of the monodic fragment of the most important common knowledge pred- 
icate logics (the full logics are known to be not recursively enumerable) 
and single out a number of their decidable fragments. On the other hand, 
it is proved that the addition of the equality symbol to the monodic frag- 
ment makes it not recursively enumerable. 



1 Introduction 

Ever since it became common knowledge that intelligent behaviour of an agent 
is based not only on her knowledge about the world but also on knowledge about 
both her own and other agents’ knowledge, logical formalisms designed for rea- 
soning about knowledge have attracted attention in artificial intelligence, com- 
puter science, economic theory, and philosophy (cf. e.g. the books [5,16,13] and 
the seminal works [8,1]). In all these areas, one of the most successful approaches 
is to supply classical — propositional or first-order — logic with an explicit epis- 
temic operator Ki for each agent i under consideration. Kitp means that agent i 
knows (or believes) (p, K 1 K 2 P says then that agent 1 knows that agent 2 knows 
ip, and the schema of positive introspection Kitp —>■ KiK^ip states that agent i 
knows what she knows. In the first-order case this language is capable of formal- 
izing the distinction between ‘knowing that’ and ‘knowing what’ (i.e., modalities 
de dicto and de re): the formula Ki3x name(a;,?/) stands for H knows that y has 
a name,' while 3xKiX\sme(x,y) means H knows a name of y.' 

There can be different interpretations of the knowledge operators (e.g. with 
or without positive or negative introspection), and for many of them transparent 
axiomatic representations have been found (cf. e.g. [7,5]). On the other hand, the 
possible worlds semantics [8] provided a framework to interpret this language: 
in a world w agent i knows p if and only if p holds in all worlds that i regards 
possible in w (the difference between various understandings of Ki is reflected 
by different accessibility relations among the worlds). 

The situation becomes much more complicated when — in order to describe 
the behavior of multi-agent systems — we extend the language with one more 
modal operator, C, to capture the eommon knowledge of a group of agents. Such 
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an operator was required for analyzing conventions [14], coordinizations in multi- 
agent systems [5], common sense reasoning [15], agreement [1,2], etcd Although 
the intended meaning of the common knowledge operator involves infinity: C<p 
stands for the infinite conjunction of the form 



K\ip A K\K2g:> A K2K\K2^p A . . . , 

both natural possible worlds semantics and clear inductive axiomatizations have 
been found for propositional common knowledge logics [7]. (The new operator, 
however, considerably increases the computational complexity of these logics — 
from PSPACE to EXPTIME; consult [5].) 

But real problems arise when we try to combine the common knowledge op- 
erator with the first-order quantifiers. First, no common knowledge predicate 
logic with both a finitary (or at least recursive) axiomatization and a reasonable 
semantics has ever been constructed! And second, the common knowledge pred- 
icate logics determined by the standard possible worlds semantics are known 
to be not recursively axiomatizable (and so not recursively enumerable) [17]. 
Thus, similar to second-order logic or first-order temporal logic, it is impossible 
to characterize common knowledge predicate logics syntactically. In some sense 
this means that neither we nor the Turing machine have the capacity of under- 
standing the interaction between common knowledge and quantifiers. Moreover, 
this is true of even very small fragments of the logics, say, the monadic or two- 
variable fragments (see [17]). 

Does it mean that we should completely abandon the idea of using common 
knowledge predicate logic? Still there exist manageable fragments with non- 
trivial interaction between the common knowledge operator and quantifiers. 

A promising approach to singling out non-trivial decidable fragments of first- 
order modal and temporal logics has been proposed in [9,20]. The idea is to 
restrict attention to the class of monodic^ formulas which allow applications of 
modal or temporal operators only to formulas with at most one free variable. In 
the epistemic context, monodicity means, in particular, that 

— we have the full expressive power of first-order logic as far as we do not apply 
epistemic operators to open formulas; 

— we can reason about agents’ knowledge of properties, for instance, 

Vx (C loves( Jo/m, a;) V C ^\o\/es{ John, x)) 

(‘for every object x, it is a common knowledge whether John loves a;’); how- 
ever, we are not permitted to reason about agents’ knowledge of relations, 
say 

Vx, y {C loves(a:, y) J C ^loves(a;, y)) 

(‘for all pairs x, y, it is a common knowledge whether x loves y’). 

^ An alternative approach adds infinitary operators to the language, see [10,11]. 

Monody is a composition with only one melodic line. 
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The main aim of this paper is to show that the monodic fragment of com- 
mon knowledge predicate logic turns out to be quite manageable. First, we show 
that for almost all interesting interpretations of the operators Ki the monodic 
fragment of the valid formulas {without equality) can be finitely axiomatized. 
Moreover, we observe that a number of natural subclasses of the monodic frag- 
ment, say, with only monadic predicates or two variables, are decidable. On the 
other hand, it is proved that the addition of the equality symbol to the monodic 
fragment makes it not recursively enumerable. 



2 First-Order Logics of Common Knowledge 

The logics we deal with in this paper are all based on the language we call 
CC, which extends the standard first-order language (without equality) with 
a number of epistemic operators, including the operator expressing common 
knowledge. The alphabet of C£ consists of: 

— predicate symbols Pq, Pi, . . . , 

— individual variables xq,xi, . . . , 

— individual constants cq, ci, . . . , 

— the booleans A, 

— the universal quantifier \/x for each individual variable x, 

— a finite number of knowledge operators Ki, . . . , Kn, n > 1, and 

— the common knowledge operator C. 

We assume that the set of predicate symbols is non-empty and that each of 
them is equipped with some fixed arity; 0-ary predicates are called propositional 
variables and denoted hy po,pi, ... . The individual variables together with the 
individual constants form the set of CC-terms. The set of CC-formulas is defined 
as follows: 

— if P is an n-ary predicate symbol and ti, . . . , are terms, then P{t\, . . . , t^) 
is a formula; 

— if and if are formulas, then so are <p A if and 

— if is a formula and x a variable, then Wxip is a formula; 

~ if is a formula and i < n, then Kiip and Ctp are formulas. 

Throughout the paper we make use of the following abbreviations: T, T, ip\/ ip, 
ip^if,(pi-^if, and 3xip, which are defined as usual, as well as Eip p everyone 
knows if’) which stands for Kiip A • • • A Kntp. 

The language CC is interpreted in first-order Kripke models which are struc- 
tures of the form = (3", D, I), where 3 = {W, R\,. . . , Rn) is the underlying 
Kripke frame {W yf 0 is a set of worlds and the Ri are binary relations on W), 
D is a, nonempty set, the domain of and / a function associating with every 
world w £W a first-order structure 

/(«;) = (a 
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in which is a predicate on D of the same arity as Pi (for a propositional 

variable pi, the predicate is either T or _L), and is an element in D 

such that for any u,v G W. The latter means that constants are 

treated as rigid designators in the sense that they designate the same object in 
every world. To simplify notation we will omit the superscript / and write P™, 
c“, etc., if / is clear from the context. 

Remark 1. Note that we assume domains to be constant. Axiomatizations for 
the case of expanding or varying domains can easily be obtained from our results. 

An assignment in Z? is a function o from the set var of variables to D. The 
value (or simply r“ if understood) of a term t under a in is a(r), if 

T is a variable, and otherwise, where w is some (any) world in W . The 

truth-relation (Wt,w) (or simply w (p) in the model in the world w 

under the assignment o is defined inductively as follows: 

— w |=“ Pi(Ti, . . . , r„) iff (r“, . . . , r“) € P™; this fact will also be written as 
I(w) )=“ P,(ti,...,t„); 

— w |=“ Ip A X w |=“ Ip and w |=“ y; 

— w |=“ ^%p iff w Ip; 

— w yx'tp{x, yi, . . . , yn) iff w |=^ "tpix, yi, . . . , y„) for every assignment b in 
D that may differ from a only on x; 

— w |=“ KiXp iff V |=“ Ip for all w G IT such that wRiV; 

-- w |=“ Cip iff u |=“ V' for all v such that w(ljj<.„ Ri)~^v, where the superscript 
+ means taking the transitive closure of Ui<n 

For a set of formulas P, a model a world w and an assignment a, we write 
w P to say that w \=" (p for every (p G P.ln this case P is said to be satisfied 

in By 3" ^ P we mean that P is valid in 3, be., (9Jt, w) P holds for every 

model based on 3, every assignment a in it, and every world w in 3- 

Different epistemic logics correspond to different classes of frames. Usually 
these classes are determined by combinations of the following properties: re- 
ffexivity (denoted by r), transitivity (t), seriality (s), and euclideanness (e). We 
denote by F'' the class of all reflexive frames, by F''® the class of all reflexive and 
euclidean frames (i.e., the class of frames with equivalence relations), etc. F® is 
the class of all frames. 

For a class F of frames, we define L{F), the logic of F, to be the set of all 
C£-formulas that are valid in all 3 G F. Here is a list of standard logics of 
common knowledge: = L(F®), = L(F''), KT>^ = L(F®), K4^ = L(F‘), 

S4^ = P(F^‘), KD45^ = L(F®‘®), S5^ = L(F-). 

3 Axiomatizing the Monodic Fragment 

As was shown in [17], none of the logics listed above is recursively axiomatiz- 
able. Moreover, the restriction of these logics to such ‘orthodox’ fragments as 
the monadic or two-variable formulas does not bring a relief: they are still not 
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recursively enumerable. By analyzing proofs of these ‘negative’ results, one can 
observe that all of them make use of formulas asserting that some agents know 
relations between two objects. On the other hand, the results of [18] establish- 
ing decidability of epistemic description logics (in which epistemic operators are 
applicable only to unary predicates) give some hope that the fragment without 
such formulas can be more manageable. 

Definition 1 (monodic formulas). Denote hyCLi the set of all CC- formulas 
ip such that any subformula of p of the form Kiif or Cip has at most one free 
variable. Such formulas will be called monodic. For a class F of frames, let 
Li(F) = L{f) nCCi- In other words, Li(F) is the monodic fragment of the 
logic L{f). 

From now on all formulas are assumed to be monodic. 

In this section we give axiomatizations of the monodic fragments of the epis- 
temic logics defined above. (These axiomatizations are first-order extensions 
of those in [7].) To begin with, we axiomatize the monodic fragment of K(C, 
i.e., Li(F^). This axiomatic system, denoted by K^, has the following axiom 
schemata and inference rules: 

Axiom schemata (over formulas in C£i): 

— the set of axiom schemata from some axiomatization of classical first-order 
logic, 

— Ki{p ^ -0) ^ {Kip Ki-ip), for i < n, 

— Cp E{p A Cp), 

— Ki^xf} yxKiif. 

Inference rules (over formulas in C£i): 

— the rules of classical first-order logic, 

p 

— , for i <n, 

K^p 

p E{tp A p) 
p Cip 

The monodic fragments of the remaining logics are axiomatized by adding to 
the corresponding standard axiom schemata: 

Ad- K^p -^Ki^p, i < n, 

At'. Kip ^ p, i < n, 

Ap. Kip KiKip, i < n, 

A^: ^Kip —>■ Ki^Kip, i < n. 

Namely, T,^, KD^ and A4(C as the axiomatic systems obtained by adding to 
the schemata At, Ad, and A^, respectively. is plus At. KDAS'p 
is A4(C extended by Ad and A^, and S5^ is KD45^ plus At. 

Given an axiomatic system S, we denote by hs its consequence relation. Our 
aim now is to prove that the defined systems indeed axiomatize the monodic 
fragments of our common knowledge logics. That is, we are going to show that 
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for every monodic formula (/J, we have iff (p S iff ip is valid in all 

frames from F“, and similar claims for the other logics. 

The easy ‘only if’ part of these claims, i.e., correctness, follows from well- 
known results (consult e.g. [5,3]) and the almost obvious fact that the rule ip 
E{'tp A ip) /ip Ci[) preserves validity. The ‘if’ part, i.e., completeness, is much 
more complicated. It will be proved in the next section. 



4 Completeness 

Given a set F of C£i-formulas, we denote by con{F) and sub{F) the sets of all 
constants and subformulas of formulas in F, respectively; subc{F) is defined as: 

subc{F) = sub{F) U A C'ip),ip A Cip^ A C'lp) : Cip G sub{F), i < n}. 

Let sm6^(T) = {-•tp : ip G subc{F)} U subc{F) and let subn{F) be the subset of 
sub/p{F) containing only formulas with < n free variables. For instance, subo{F) 
denotes the set of sentences in sub//{F). (Note that sm6„(T) is not necessarily 
closed under subformulas and that modulo equivalence we may assume that 
subn{F) is closed under ^.) In what follows we will not be distinguishing between 
a finite set F of formulas and the conjunction /\ T of formulas in it. 

Let a; be a variable not occurring in F . Put 

subx{F) = {ip{x/y} : 'tp{y) G subi{F)} U ± : i < n} 

For the rest of this section we fix an arbitrary C/li-sentence ip. 

Definition 2 (type). By a type for ip we mean a boolean-saturated subset t of 
subx{ip), i.e., 

— 'ipAx&t iff 'f’&t and x G t, for every ip A \ & subx{ip); 

— -nip £ t iff Ip ^ t, for every -nip G subx{ip). 

We say that two types t and t' agree on subo{if) iftC] subo{(p) = f D subo{ip). 
Given a type t for ip and a constant c G con{ip), the pair {t,c) will be called an 
indexed type for ip (indexed by c) and denoted by tc{x) or simply tc. 

Definition 3 (state candidate). Suppose T is a set of types for ip that agree 
on subo{ip), and = {{t,c) : c G con(ip)} a set of indexed types such that 
{t : {t,c) G C T and for each c G con(ip), T™” contains exactly one pair 

of the form {t, c). The pair £ = (T, T™") is called then a state candidate for ip. 
A pointed state candidate for ip is the pair ip = (€,t), where t is a type in T, 
called the point o/ip. With € and ip we associate the formulas 

oc = y/y t{x) AVx \J t{x) A y/y t{c), /Ssp = oc A t. 

teT teT 

In what follows S ranges over the axiomatic systems introduced in Section 3. 
We remind the reader that a formula x is said to be S'-consistent if I/s ->x. 
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Definition 4 (suitable pairs). (1) A pair of types for (p is called i- 

suitable for S, i < n, if the formula t\ A ^Ki^t 2 is S-consistent. 

(2) A pair (€i,€ 2 ) of state candidates is i-suitable for S, i < n, if A 

is S-consistent. 

(3) A pair (^ 1 ,^ 2 ) of pointed state candidates is z-suitable for S, i < n, if 

/3fpi A is S-consistent. In this case we write Ai ^ 2 - 



Lemma 1 . (i) For every finite S-consistent set F of CL\- formulas, there is a 
pointed state candidate ^ = (£, t) for ip such that /\'F A is S-consistent. 
Moreover, if tp € subx(p) and ip G'F, then ip Gt. 

(ii) Suppose F is a finite set of CL\-formulas and ~^Ki9 is a formula in 
subx{p) such that /\'F A ^Ki9 is S-consistent. Then there exists a pointed state 
candidate fp = (£, t) for p such that ^9 Gt and /\T A is S-consistent. 

Proof, (i) Denote by Pep the disjunction of all formulas ^ a pointed state 
candidate for p. As Pp, is classically valid, it is provable in S, hence /\'F A Pp, is 
S'-consistent. It follows that there is a disjunct /3sp of such that /\T A P<:p is 
S'-consistent. Now, if ip G T C\ subx{p) and t is the point of ip, then ip G t, for 
otherwise —'ip G t, which is a contradiction. 

(ii) If f\F A ~^Ki9 is S'-consistent, then so is /\ '?' A ^Ki^{-^9 A P^f). It follows 
that there is a pointed state candidate ip with point t such that /\ F A^Ki^{^9A 
/3sp) is S-consistent. Clearly, -^9 G t, and we are done. 

Note that Lemma 1 will hold true if we replace x by some constant c. 

Lemma 2. (i) If a pair (€i,€ 2 ) of state candidates for p is i-suitable for S, 
i <n, then: 

1. for every t gT\ there exists a t' G T 2 such that (t,t') is i-suitable for S; 

2. for every t' G T 2 there exists at GT\ such that {t,t') is i-suitable for S. 

(ii) Suppose that a pair of types (t,f) is i-suitable for S. Then: 

1. Ip Gt' whenever Kiip G t; 

2. if A 4 G S, then Kiip G t' whenever Kiip G t; 

3. if {D, A 5 } C S, then Kiip G t whenever Kiip G t' ; 

4 . if {D, A 4 , A^} C S or {T, A 5 } C S, then Kiip G t iff Kiip G t' . 

(iii) Suppose {t,t') is i-suitable for S . ThenCip G t implies Cip G t' . If {A 4 , A^} C 
S, then Cip G t iff Cip G t' . 

Proof, (i) Suppose that t G Ti but there is no t' G T 2 for which {t,t') is i- 
suitable for S. This means that \~s t ^ Ki^t', for each t' G T 2 , and so 
\~S t ^ Ki^\J . Then we have \~s ^ Ki3x^\J . Since hg 

Vt'eT 2 hg ^ 3xt, we finally obtain I -5 a^i ^ 

contrary to S-consistency of A ^Ki^atr^. Claim (i.2) is proved in a similar 
way. 




336 Holger Sturm, Frank Wolter, and Michael Zakharyaschev 



(ii) Suppose that Kiip e t but i) ^ t' . Then e t' , I -5 Kiip Ki^t' , and 

so t A is S'-inconsistent, which is a contradiction. 

Now suppose that S contains A4, Kitp G t, but Kiip ^ t' . Then ^Ki%p G t' . 
Hence hs KiKi-tp . It follows from A4 that I -5 Kiip Ki^t' , and so 

Kiip A^Ki^t' is S'-inconsistent, contrary to S-consistency of Claims (i.3) 

and (i.4) are proved analogously. 

(iii) Suppose Cip G t. Then E{ip A Cip) G t and so Ki{ip A Cip) G t, for i < n. 
By (ii.l), Ip A Cip G t' , from which Cip G t' . 

If Cip G t' then, as we know, Ki{ip A Cip) G t', for z < n. So if {A4, A^} C S, 
then we have by (ii.4), ip A Cip G t, and so Cip G t. 



Definition 5 (basic tree). Let T = (IT, <1, . . . , <„) he a structure with pair- 
wise disjoint binary relations <i on W such that (w, lJi<„ intransitive 

treeP By a basic tree for ip we mean the pair (T, ct), where a is a map associ- 
ating with every w GW a state candidate a{w) = {Tyj,T)P) for ip. A basic tree 
is called a basic S-tree if acr(tu) is S-consistent, for every w G W, and the pair 
(a(wi), cr(w2)) is i-suitable for S whenever wi <i W2- 



Definition 6 (run). A run r in a basic S-tree (T, cr) is a map associating with 
every w GW a type r{w) G such that 

— the pair (r{wi),r{w2)) is i-suitable for S whenever w\ <i W2; 

— if ^ Kiip G r{w) then ip ^ r{w') for some w' >i w; 

— if ^Cip G r{w) then ip ^ r{w') for some w' such that tc(Ui<n . 



Definition 7 (quasimodel). A basic S-tree (T, cr) is called an S-quasimodel 
for p if 

— for all w GW and t G (^{w) = (T^,, T ™) ), there exists a run r in (T, a) 
such that r{w) = t; 

— for every constant c G conip), the function Vc defined by rJw) = t, for 

{t, c) G wGW, is a run in (T, a) . 

We say p is satisfied in (T, a) if there exists w G W such that A p is 

S-consistent. 

Theorem 1 . If p is satisfiable in an S-quasimodel for p, then p is satisfiable 
in a model based on a frame for S. 

® We remind the reader that 0 = (IT, <) is an intransitive tree if (i) 0 is rooted, i.e., 
there is wo G IT (a root of 0) such that wq <* w for every w G IT, where <* is the 
transitive and reflexive closure of <, (ii) for every w G IT, the set {u G IT : i><* w} is 
finite and linearly ordered by <*, (iii) every world v in 0, save its root, has precisely 
one predecessor, i.e., \{u GW : u < u}| = 1, and (iv) the root wo is irreflexive, i.e., 
—’Wo < Wo- 




Monodic Epistemic Predicate Logic 337 



Proof. For every monodic formula ip{y) of the form Kixiy) or Cxiy) with one 
free variable y, we reserve a unary predicate P^{y). Likewise, for every sentence 
= KiX or 'if = Cx we fix a propositional variable p.^. Pip{y) and p.^ will be 
called the surrogates for V'(y) Etnd if. 

Given a monodic formula if, we denote by if the formula that results from 
if by replacing all subformulas of the form Kix(y), KiXi ^nd Cx, which 

are not within the scope of another epistemic operator, with their surrogates. 
Thus, if contains no occurrences of epistemic operators, i.e., it is a purely first- 
order formula; we will call if the C-reduct of if. For a set of C/li-formulas P , let 

r = {%f \ %f ^ r}. 

Now suppose (fi is satisfied in an S'-quasimodel (T, <t), T = {W, <i, . . . , <„). 
So there is w* G VF such that p A is <S'-consistent. It follows that the C- 

reduct ^AOcr(tu*) is consistent with respect to classical first-order logic. Moreover, 
by Definition 5, ao-(u)) is 5-consistent and is first-order consistent, for every 

w & W. So, for each w G W, we can find a structure I (in) ^ acr(w)- We may also 
assume that I(w*) p, for some assignment o*. 

Take a cardinal k > Hq exceeding the cardinality of the set 17 of all runs in 
(T, a) and put 

D = {(r,f) : r G < k}. 

Without loss of generality we can assume that D is the domain of the first-order 
structures I(w) satisfying the oia{w), that c™ = (rc,0), and that 

r(w) = {if& sub,,(ip) : I(w) |= V’KaO]}: (1) 

for all runs r and f < k. (Note that the underlying first-order language does not 
contain equality; for details see [9], Lemma 9.) 

Let us now define the underlying frame ^ of the model we are constructing. 
Its set of worlds is W. The accessibility relations Ri depend on S. Namely, we 
define Ri to be 



~ <i if •S' = or S' = KD^] 

— <iU {(w,w) : w G IF} if S = T^; 

— the transitive closure of <i if S = 

~ the reflexive and transitive closure of <i if S = S4(}; 

~ <f U {{w,w') : G W(v <f wSzv <f w' Sz^3u u <i u)| if S = KDA5^; 

— the reflexive, symmetric and transitive closure of <i if S = S5. 

Note that for S = KD^ the Ri are serial because in this case every S-consistent 
type for ip contains at least one formula of the form ~^Kiif. For S = KD4P>(f the 
Ri are clearly serial. Suppose w\RiW and wRiW 2 . If has no <i-predecessor, 
then wi <f W 2 and so w\RiW 2 . Otherwise, there are Vj, for j = 1,2, such that 
Vj <f Wj, Vj <f w and the vj have no <i-predecessors. Since T is an irreflexive 
tree, we get v\ = V 2 . Thus v\ <1' w\ and v\ W 2 . By the definition of Ri, it 
follows that w\RiW 2 . Hence Ri is transitive. Similarly one can show that Ri is 
euclidean. 
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Thus we have the model = (3", i?i, . . . , i?„, /). By induction on the con- 
struction of V' € sub{ip) we will show now that for every assignment o 

I{w) Ip iff (DJt,w) |=“ Ip. 

The basis of induction, i.e., the case where ip = Pi(ri, . . . , Tm) is clear; for then 
Ip = ip. The induction step for ip = ipi /\ ip2, ip = ~''ipi, and ip = ^yipi follows 
by the induction hypothesis from the equations ipi /\ ip2 = 'tpi ^^2, “'V'l = 
yyipi = yyipi- Let ip = Kix{y) and assume that a{y) = (r, ^). (If ip is a, sentence, 
y is any variable.) We then have: 

I{w) [=“ Kixiy) ^1 PKixiy) 

^2 KiX{x) G r{w) 

<t^3 Vu {wRiV x{P) G r{v)) 

Vu {wRrV I{v) x{y)) 

■^5 Vv {wRiV (Tt,v) |=“ x(y)) 

4^6 (M,w) Kixiy). 

Equivalence holds by the definition of ip; <t^2 and <t^4 are consequences of 
(1). The induction hypothesis yields <t^s, and holds by definition. The only 
non-trivial case is <J4>3. 

(=^3) Suppose KiX G r{w) and wRiw' . So if w <i w' the claim follows by 
Definition 6. If S' = iL or S' = D then we are done, because Ri =<i- 

Let S = KDA 5 . By the definition of Ri, we have either w <f w' or there 
exists V such that v <f w, v <f w' and ~^3u u <i v. The former case is 
easy; we leave it to the reader and consider the latter one here. We have some 
TO G w and worlds vq,. . . ,Vm+i such that vq = v, Vm+i = w and Vj <i Vj+i 
for every j < to. By Definition 6, (r(uj), r(uj+i)) is z-suitable for S whenever 
j < TO. By Lemma 2, Kix{x) G r{vo) = r{v). Similarly, using v <f w' we 
obtain worlds such that uq = v, ui+i = w' and Uj <i Uj+\ for 

every j < 1 . Again, {r{uj),r{uj+i)) is z-suitable for S whenever j < I, and 
by Lemma 2, Kix{x) G r(ui). Using the same lemma once again, we obtain 
x{x) G r(zz;+i) = r{w'). (<^=3) is an immediate consequence of Definition 6. 
Other cases for S are treated analogously. 

Finally, let ip = Cx{y) and o(y) = (r, ^). Since the proof is similar to the 
foregoing one, we leave it to the reader. 

Thus, to prove completeness of our axiom system S, it suffices to construct 
an S'-quasimodel satisfying ip whenever p is ^-consistent. 

Lemma 3. Let fp = {€, t) he a pointed state candidate for p such that /Ssp is 
S-consistent. 

(i) If ^Kiip G t, then there exists ip' = ft' ,t') such that ip ip' and ip f t' . 
Moreover, if {t, c) G t for some constant c, then we can choose ip' = {€' , t') with 
ip <i ip' and Ip ft' so that {t', c) G €' . 
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(ii) If -^Cip G t, then there are pointed state candidates = {€j ,tj), j < k, 
with ^0 = ^ and 

^0 ^*1 ^^1 ^*2 ■ ■ ■ Vk, 

for some i\, . . . ,ik < n, such that -<'ip G tk- Moreover, if {t, c) G then we can 
choose such a sequence with {tj, c) G €.j for all j < k. 

Proof, (i) follows from Lemma 1. So let us prove (ii). Suppose that such a se- 
quence does not exist. Let T be the minimal set of pointed state candidates such 
that 

- ^er, 

— if Si G T and Si S 2 for some i, then S 2 G T. 

Let d = Vser/^®- Then hg i? ^ Kid, for all i < n. Indeed, suppose otherwise. 
Then d A ~^Kid is S'-consistent for some i < n. But then, by Lemma 1, A 
is S'-consistent for some pointed state candidate ip' ^ T. This, however, 
contradicts the definition of T, since we would have S A* for some disjunct 
/3j) of d. Hence hg 1 ? ^ Ed. Clearly, if G s for every (£*, s) G T, for otherwise 
we could construct a sequence satisfying condition (ii). Thus, \~s d ^ if and 
so hg d E{if A d). By the inference rule for C we obtain Gs d ^ Cif, and 
so hg /?sp(a;) ^ Cif, since ip G T. But then /3sp is S-inconsistent, which is a 
contradiction. 



We are in a position now to prove the main result of this section. 

Theorem 2. If S is one of the axiomatic systems defined above and (p an S- 
consistent monodic formula, then (p is satisfiable in a model based on a frame 
for S. 



Proof. In view of Theorem I, it suffices to construct an S'-quasimodel satisfying 
ip. By Lemma 1, we can find a state candidate such that ip A oc* is S'- 
consistent. We are going to construct the required quasimodel as the limit of a 
sequence 

of basic S-trees, m G uj. 

Let Wo = {w*} for some point w* and let cto(w*) = £*. Suppose now that 
(Tm, (Xm) has been already defined. For every iv G Wm — Wm-i we shall construct 
a number of new points ‘saturating’ (Jra{w) {W-\ = 0). Let € = am{w), € = 
(T, . Pick some t GT and do the following: 

(a) For every y = ~^Kiif G t we take two points and b^, add them to 

Wm, put w a^, w b^, and <Tm+i(a^) = am+i{bx) = for some 

€' underlying a pointed state candidate ip' = ft ,t') with ft,t) Ai ip' and 
if t'{x). That such a ip' exists is guaranteed by Lemma 3. If {t, c) G for 
some constant c, then we take for t' the type s with (s,c) in t. 

(b) For every y = ~^Cif G t we take two sequences a^, . . . , and 6^, . . . , 6^ 
and put 



<TA' A 



< 



m+1 



^m+1 k 



W 



.m+1 



bl ^m+l 
X ^^2 



^m+1 



b 



k 

X’ 
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and 

cr„+i(a^) = am+i{K^) = for all j < fc, 
where the form a sequence of pointed state candidates with 

{€,t) (G:^^'=) 

and ~^tp e Again Lemma 3 ensures the existence of such a sequence. If {t, c) G 
Tcon some constant c, then we take a sequence with from & for all 

j < k. 

In the same manner we consider the remaining types in T and then the 
remaining worlds v G Wm — Wm-i- Wm+i is defined as the (disjoint) union of 
Wm and the constructed new points. The relations coincide with <)" on 

Wm- For the new points their extension is defined above. The function <Tm+i 
coincides with Um on Wm and is defined above for the new worlds. Thus we have 
constructed (T^+i, CTm+i). 

Finally, put (T, a) = ((IT, <j", . . . , <™) , cr), where 

W= \JWm, <i= U = U 

m<.(jJ m<.uj m<.uJ 

It remains to show that (T, a) is an S'-quasimodel. It should be clear that the 
functions Vc are runs. So it suffices to show that, for all w G IT and t from a{w), 
there exists a run r with r{w) = t. 

First, using Lemma 2 we find a sequence 

W* = Wo <ji Wi <i 2 • • • <ij, Wk = w 

and types tj from 0 < j < k, such that tk = t and tj{x) 

is S'-consistent for all j < k. 

Let r{wj) = tj and To = {wq, ■ . ■ , Wfc+i}. Define by induction an increasing 
chain of sets T 2 IT with T — IT C To, on which we define r. Suppose Vn is 
defined. For every w G IT„ — IT„_i with r{w) = t we do the following: 

— If G t, then take v G IT„+i — T„ with w <i v and t' from a{v) such 

that t A is S'-consistent and ^ t' . This can be done because we 

always took two saturating worlds in the construction above. Put r{v) = t' . 

— If G t, then take a sequence vi,.--,Vk from IT„+i — T„ such that 

w <io I’ll 'i'l <ii ■ ■ ■ '^iki types tj from cr(vj), 1 < j < k, such that 

• (t,ti) is T-suitable for S, 

• (tj,tj+i) is ij-suitable for S, 1 < j < k, 

• i) ^tk- 

Again, this can be done since we always took two saturating sequences. Put 
r{vj) = tj for all I < j <k. 

Finally, we have to define r for all v G IT„+i where r was not defined above. 
This can be done recursively as follows. Suppose r{v) is not defined yet for some 
V G IT„+i. If r is defined already for the (unique) v' such that v' <i v, then take 
a t from a{v) such that (r{v'),t) is z-suitable for S and put r{v) = t {t exists by 
Lemma 2). Otherwise consider first v' itself. 

It is now straightforward to see that r is a run. 
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As a consequence we obtain: 

Theorem 3. Let S G {K^ ,KD^,KA'^,SA'^,KDAb'^,Sb^} and let F be 
the class of frames for S. Then for every monodic formula (p it holds that hg 
if iff ip € Li(F). 

5 Decidability 

Another important algorithmic feature of the monodic formulas is that if, roughly 
speaking, we restrict the underlying purely first-order formulas to a decidable 
class, then the resulting monodic fragments of the epistemic logics under con- 
sideration will also be decidable. In particular, we have the following: 

Theorem 4. Let F be any of the frame classes mentioned at the end of Section 2. 
Then the following fragments are decidable: 

— the monadic fragment o/Ti(F), 

— the two-variable fragment of Li{f), 

— the guarded fragment o/Li(F). 

(Note, however, that the guarded fragment of A(F^) is undecidable.) For more 
details and an idea of the proof the reader is referred to [9,20]. Actually, no non- 
trivial decidable fragments of epistemic predicate logics have been constructed 
before. 

It maybe also of interest to note that these decidability results make it pos- 
sible to construct various decidable description logics with common knowledge 
and other epistemic operators applicable to concepts and formulas (but not to 
roles; see [19]). Weaker epistemic description logics were proposed in [6,12]. 

6 Adding Equality 

In this section we show that the addition of equality to the language of monodic 
formulas restores the ‘status quo,’ namely, that all the fragments considered 
above become non-enumerable. Let CLf be the language CL\ extended with the 
equality symbol interpreted in first-order structures as identity. 

Theorem 5. Let F be any of the frame classes defined at the end of Section 2. 
Then the logic Li(F) in the language CCf is not recursively enumerable. 

Proof. Define if to be the conjunction of the following 

ipi = 3xP{x) A VxVy {P{x) A P{y) ^ x = y), 

tp 2 = (Tdx'iy (p^Ki^P(x) A ~^Ki^P{y) A ^P{x) A ~^P{y) ^ x = y), for i < 2, 

= -nC^Vx {P{x) ^ -nC^P{x)), 

= Vx i^C^P{x) C^C^P{x)), 

V's = Vx {Q{x) ^ ~^C^P{x)). 
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First we notice that for all models = {^,D,I) with g" = {W, Ri, . . . , Rn) 
and all w £ W, if (Tl,w) ^ ip then is finite. Indeed, by ^/>i, the set 

pl(w) 

is a singleton. From 'ips we get some w' for which Ri)~^w' and 

w' 1= Va; {P{x) ^ ^C^P(x)). Hence there are wo,...,tCm+i G W such that 
wq = w, Wm+i = w' and for every j < m there is some ij < 2 for which 
WjRi^Wj+i holds. In view of ■02, < 1 for every j < m, which 

yields \pP'^ 1| < m + 1. Thus it remains to show that C ). Suppose 

a G Then, by 0s, w \= -^C^P[a] and by 04 we obtain w \= C^C^P[a], 

from which w' |= P[a\. 

Second, we show that for every first-order sentence 9 containing neither P 
nor Q the following are equivalent: 

(a) 9 is true in all finite first-order structures; 

(b) Ip ^ 9^ is valid in all frames in F. 

(Here 9^ is the relativisation of 9 to Q, i.e., 9^ = 9 if 9 is atomic, ^ commutes 
with the booleans, and {\/x9i)^ = \/x (Q{x) 9f).) 

(a) (b). Suppose there is a model and a world w in it such that w \= ip 

but w ^ 9^ . Define a finite first-order structure J with domain E = 
and predicates P^ = H E. It can be easily shown by induction that for 

every formula x &nd every assignment o in P, we have J^“xiffw|=“ In 
particular, J ^ 9. 

(a) 4= (b). Let us show first that for every natural number to > 0, there are 
= {dmi Dm, Im) based on a frame Sm £ F’’® and w in Sm such that |VF| = to 
and w \= Ip. Put Wm = {wi, . . . , Wm}, Wi Wj whenever i yf j, Dm = N, and 

.Ri = {{wk,Wk+i) , {wk+i,Wk) : k < m k 31 k = 21 + 1}U {{wk,Wk) : k < to}, 
R 2 = {{wk,Wk+i) , {wk+i,Wk) : k < m k 31 k = 21}U {{wk,Wk) : k < to}. 

Finally, for each k < m, put = {0, . . . , fc— 1} and = |o^ . . . , to— 1} 

(see Fig. 1). It is easy to see that the model is reflexive and euclidean, and 
wi 1= Ip. 



P“i={0} ={0,1} ^{0,1,2} {0, ...,m-2} {0, ...,m-l} 



0 -- 

Wl 





Ri R2 Ri 

W2 W3 



O- 



Fig. 1. 



Now, to complete the proof, suppose that there is a finite first-order structure 
J with domain D such that |D| = to and J 9. Take the model and the 
world w ^ Ip constructed above. Without loss of generality we can assume that 
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Qim(w) _ expand to a model by interpreting each predicate 

symbol Pi as follows: ^ = P^ , for each w' G Wm- Now, for every first- 

order formula y (without P, Q) and every assignment a in Z?, we have J \=° X 
iff tc) Therefore, w) ^ 0^ , and so ^ ^ 9^ is not valid in F'"® 

(which is contained in all our frame classes). 

It remains to recall that, by Trakhtenbrot’s theorem (see [4]), the set of first- 
order sentences that are valid in finite structures is not recursively enumerable. 

Acknowledgments. The authors would like to thank Nobu-Yuki Suzuki for his 
helpful comments. While carrying out this research the first author was sup- 
ported by the Deutsche Forschungsgemeinschaft. 
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Abstract. The aim of this paper is to combine, into a single logic pro- 
gramming framework, the hitherto separate forms of reasoning of pref- 
erences and updating. More precisely, we dehne a language capable of 
considering sequences of logic programs that result from the consecutive 
updates of an initial program, where it is possible to define a priority re- 
lation among the rules of all successive programs. Moreover, within the 
framework, the priority relation can itself be updated. 

In order to define a declarative semantics for the language, we start by 
reviewing the declarative semantics of updates of [1], and by presenting 
a definition of a semantics for preferences, shown equivalent to the one 
in [5], in a form suitable for its integration with the updates one. 

Before the conclusions and mention of future work, we present two illus- 
trative examples of application of the framework. 



1 Introduction 

In recent times, there has been a spate of work on reasoning with preferences and 
also, but separately, another spate of work on knowledge updating, both of which 
in the logic programming context. This interest has followed in the wake of a more 
general examination of flexible and dynamic forms of non-monotonic reasoning 
within artificial intelligence (AI). The present writing aims at combining these 
two heretofore separate forms of reasoning, preferring and updating, again in the 
purview of logic programming. We shall show how they complement each other, 
in that preferences select among pre-existing models, and updates actually create 
new models. Moreover, preferences may be enacted on the results of updates, 
and updates may be pressed into service for the purpose of changing preferences. 

Forms of preference which have been intensely studied include specificity in 
taxonomic defaults, authority as well as temporal overriding in legal reasoning, 
priority of effect rules over inertia rules in causal reasoning, more likely faults in 
model-based diagnosis, preferred configurations in system synthesis, and scenario 
considerations in decision making. Many prioritized versions of existing non- 
monotonic formalisms have, already for some time, been developed, namely for 
circumscription, for hierarchical auto-epistemic logic, for default logic, for belief 
revision, and for abduction. In the case of logic programming (LP), research on 

* Work partly supported by PRAXIS XXI project t^2/2.1/TIT/1593/95 MENTAL. 
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the topic of preferences is much more recent. Cf. [4,5] for additional motivation, 
comparisons, applications, and references. Here, we expressly adopt the stable 
models based semantic framework of Brewka and Eiter [5] , though replacing it 
with an equivalent formulation to bring it in line with our own stable models 
based update framework, with which we enmesh it. Another paramount reason 
for this choice of preference semantics are the two desirable principles (cf. Section 
3) and the properties that semantics obeys, as spelled out by their authors. 

In what concerns updates, its significance for AI has long been the object of 
much study [14,9,7]. In the LP setting, the accomplishments in this topic have 
likewise been garnered at a much later date [1,6,11,13,12,15]. Herein we adopt 
the stable models based update framework of [1] for the purpose of expanding 
it with the aforesaid preferences one. Sample prototypical applications of LP 
updates have included legal knowledge evolution [2], modelling of actions [3], 
taxonomic inheritance [6], and software development. 

Preferences and updates are different forms of reasoning and serve different 
goals and applications. Preferences are used along with incomplete knowledge, 
when this is modeled with default rules. In such a setting, due to the incom- 
pleteness of the knowledge, several models may be possible. Preferences act by 
choosing among those possible models. A classical example is the birds-fly prob- 
lem, where the incomplete knowledge contains the rules that birds normally fly 
and penguins normally don’t. Given an individual which is both a penguin and 
a bird, two models are possible: one, using the one rule, where the individual 
flies; another, using the other more specific rule, where it doesn’t. Preferences 
among rules can then be used to choose which one. 

Updates are used to model dynamically evolving worlds. The problem arising 
here being, given a piece of knowledge describing the world, and given a change 
in the world (be it a rule or fact), how to modify the knowledge to cope with 
that change. The knowledge may itself be complete or incomplete: that’s not the 
key issue in updates; rather, the key issue is about the process of accomodating, 
in the represented knowledge, any changes in the world. In this setting it may 
well happen that change in the world contradicts previous knowledge, i.e. the 
union of the previous knowledge with the representation of the new knowledge 
has no model. It is up to updates to remove from the prior knowledge represen- 
tation a piece that changed, and to replace it by the new one. In this respect, 
mark well the distinction between update and revision of the knowledge, well 
broughtout e.g. in [14]. Whereas in the former knowledge changes due to changes 
in the world, in the latter incomplete knowledge is changed due to additional in- 
formation (further completing the knowledge) about a static world view. These 
processes are different, and lead to different results. For example, suppose that 
your knowledge consists of a single rule stating that you have a flight booked for 
London, that is either for Heathrow or for Gatwick. If new information, stating 
that it is not for Heathrow, arrives thereby completing this knowledge (e.g. a 
call from your travel agency, clarifying this issue), then you should conclude that 
the flight is booked for Gatwick. If, the same information (^Heathrow) arrives 
due to a change in the world (e.g. you heard on the radio that all flights for 
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Heathrow have been cancelled), then you should not conclude now that your 
flight is booked for Gatwick. 

One way to look at revision is to consider any prior rules as defeasible, add the 
new knowledge to the previous one, and assign preference to this new knowledge 
over the old one (revision as chronological preference). This stance is justifiable 
in revision: our knowledge is incomplete; to make it less incomplete, when some 
new information arrives it should be given preference over the previous. But 
a similar rationale makes little sense in updates. Suppose that at some point 
we know that normally quakers are pacifists, and that the republican Nixon is 
a quaker. Forthwith we can conclude that Nixon is a pacifist. Now something 
happens in the world so that republicans tend to be belicists. A new rule, stating 
that normally republicans are belicists, is added as an update. What should we 
conclude about Nixon? In our opinion, nothing different from a situation where 
both rules are given at the same time: for Nixon, there is a conflict, and two 
models exist - one where he is considered pacifist, and the other where he isn’t. 
It may well happen that, given the conflict among such defeasible rules in our 
incomplete knowledge, one may want to give preference to the quakers-pacisfist 
rule over the other rule. 

In many real applications one is bound to have just incomplete knowledge 
about the world, default rules, and may want to be able to deal with a dynami- 
cally evolving world, where these rules may change in time. In such a situation 
preferences may be needed to choose among various possible models of the world, 
whereas updates are needed to deal with the knowledge on the evolution of the 
world. In this evolution, preferences themselves may change in time. Thus, a 
combination of both reasoning forms into a single framework is needed. 

Consider the following example, where default rules as well as preferences 
change over time, which requires a combination of preferences and updates, 
including the updating of preferences themselves. 

Example 1 (A sad story). (1) In the initial situation I am living and working 
everyday in the city. (2) Next, as I have received some monies, I conjure up other, 
alternative but more costly, living scenarios, namely travelling, settling up on 
a mountain, or living by the beach. And, to go with them, also the attending 
preferences, but still in keeping with the work context, namely that the city 
is better for that purpose than any of the new scenarios, which are otherwise 
incomparable amongst themselves. (3) Consequently, I decide to quit working 
and go on vacation, supported by my increased wealth, and hence to define my 
vacation priorities. To wit, the mountain and the beach are each preferable to 
travel, which in turn gainsays the city. (4) Next, I realize my preferences keep 
me all the while undecided between the mountain and the beach, and opt for the 
former. (5) Forthwith, I venture up the mountain, only to become ill on account 
of the height, and a physician advises me against too much sun exposure, be it 
at the mountain or the beach level. (6) So, I update my knowledge regarding 
health, and my concomitant priorities, and thus travel becomes the choice par 
excellence. (7) I Anally run out of money for travel and return, still ill, to the 
city, cannot work, and continue my sad vacation there. 
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Despite their differences, the preference and the update LP approaches we 
adopt are also similar, in that both can be envisaged as wiping out rules. In 
the preference setting, one wipes out less preferred rules in order to select only 
some among the available stable models. In the update setting, one wipes out 
rules that are overruled by new rules, thereby engendering new models, including 
cases when there were none before the update took place. Looking at both in 
a similar way facilitates their coming together under one same framework. For 
preferences it makes all the sense to employ some (strict) but partial order 
on rules, for there are cases where one wishes to allow incomparable rules to 
defeat but not wipe out one another. For updates, a linear temporal order is 
employed, and alternative results may be obtained via distinct but nevertheless 
linear updating sequences, to produce a tree. A root node always exists, if need 
be the initial empty program. 

The sequel is organized as follows. First, we recap the fixpoint semantics of 
updates, which relies on erasing rules rejected by an update. Second, we define 
a fixpoint semantics for preferences which resorts to erasing unpreferred rules. 
Third, on the basis of these, we proffer a joint fixpoint semantics for both updates 
and preferences. Finally, conclusions and future work are brought out. 

2 Dynamic Logic Programs 

In this section we recall the framework of Dynamic Logic Programming (DLP) 
[1] that, as motivated above, can be used to model the evolution of logic program 
through sequences of updates. 

To represent negative information in logic programs and their updates, DLP 
allows for the presence of default negation in rule heads 

Definition 1 (Generalized logic program). A generalized logic program in 
the language L is a finite or infinite set of ground rules r of the form: 

Lq < Lx, . ■ . , Ln- n ^ 0 

where each Li is a literal in C (i.e. an atom or a default literal not A where A is 
an atom). By header) we mean Lq, by body{r) the set of literals {Li , . . . , L„}, by 
bodyposir) the set of all atoms in body{r), and by bodynegir) the set of all default 
literals in body{r). We refer to bodypos{r) as the prerequisites of r. Whenever L 
is of the form not A, noth stands for the atom A. 

The semantics of generalized logic programs is then defined as a general- 
ization of the stable models semantics [8]. First note that, instead of using the 
fixpoint operator T(M), one may take default literals in rule bodies as new 
propositional variables, add a fact not A for every A M , and then compute 

^ See [1] for an explanation on why default negation is needed in rule heads, rather 
than explicit negation. Note that a defanlt negated atom in a rule’s head means that 
the atom shonld no longer be assumed true, whilst an explicit negated atom would 
mean that the atom should become false. In an update context this difference is 
similar to the difference between deleting a fact and asserting its complement. 
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the least model of the resulting definite program. It is easy to check that the 
resulting set of atoms, not of the form not A, will be exactly the same as in 
r{M). Moreover, for every fixpoint of F{M), A ^ M all rules of the program 
with head A have a false body in M. Thus, if one is only interested in fixpoints, 
instead one may add not A for just every A having no rule with a true body in 
M . This approach views stable models as deriving not A for every atom A which 
is not “supported” in the program by the model. 

Now, since one can have default literals in rule heads, there are more ways of 
deriving them. But the previous one remains. This is the basic intuition behind 
the definition of stable models for generalized programs: given a model M, first 
add facts not A for every A with no rule with true body in M; M is a stable 
model if the least model obtained after such additions coincides with M, where 
M has been enlarged with new propositional variables not A for every A ^ M . 

Definition 2 (Default assumptions). Let M he a model of P. Then: 
Default{P,M) = {not A \^r G P : head{r) = A A M \= body{r)} 



Definition 3 (Stable Models of Generalized Programs). A model M is a 
stable model of the generalized program P iff M = least{P U Default{P, M)) 

For normal programs, this definition is equivalent to the original definition of 
stable models [8]. As shown in [1], it also coincides with the semantics presented 
in [10] when the latter is restricted to the language of generalized programs. 

In DLP, sequences of generalized programs Pi©. . .0P„ are given. Intuitively 
a sequence may be viewed as the result of, starting with program Pi, updating 
it with program P 2 , . . ., and updating it with program P„. In such a view, 
dynamic logic programs are to be used in knowledge bases that evolve. New 
rules (coming from new, or newly acquired, knowledge) can be added at the end 
of the sequence, bothering not whether they conflict with previous knowledge. 
The role of dynamic programming is to ensure that these newly added rules are 
in force, and that previous rules are still valid (by inertia) as far as possible, i.e. 
they are kept for as long as they do not conflict with newly added ones. 

The semantics of dynamic logic programs is defined according to the rationale 
above. Given a model M of the last program Pn, start by removing all the rules 
from previous programs whose head is the complement of some later rule with 
true body in M (i.e. by removing all rules which conflict with more recent ones). 
All other persist through by inertia. Then, as for the stable models of a single 
generalized program, add facts not A for all atoms A which have no rule at all 
with true body in M, and compute the least model. If M is a fixpoint of this 
construction, M is a stable model of the sequence up to P„. 

Other possible views on and usage of DLP, justify slight generalizations of the 
above informally described language and semantics. In general, the distinguished 
programs represent knowledge true at some state s, where different states may 
stand for different stages of knowledge in the linear evolution of the knowledge 
base (as above), but also for different time points in possible future evolutions of 
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the knowledge, or even for knowledge of ever more specific objects organized in 
a hierarchy. In the latter case, each program contains the rules that are specific 
to the object under consideration, and rules from programs above in the hier- 
archy are inherited just as long as they do not conflict with the more specific 
information (for more on this stance see [6]). These other views justify a tree-like 
structure of programs (rather than a sequence), and also that dynamic programs 
can be queried at any state, rather than only at the last one. 

Definition 4 (Dynamic Logic Program). Let S be an ordered set with a 
smallest element sq and with the property that every s G S other than sq has 
an immediate predecessor s — 1 and that sq = s — n for some finite n. Then 
: i G S} is a Dynamic Logic Program, where each of the PiS is a generalized 
logic program. 

Definition 5 (Rejected rules). Let : i G S} he a Dynamic Logic Pro- 

gram, let s G S, and let M he a model of Ps ■ Then: 

Reject{s, M) = {r G Pi \ 3r' G Pj, head{r) = not head{r') A i < j < s A 

M \= body{r')} 

To allow for querying a dynamic program at any state s, the definition of 
stable model is parameterized by the state: 

Definition 6 (Stable Models of a DLP at state s). Let ®{Pj : i G S} be 

a Dynamic Logic Program, let s G S, and let V = Ui<s Pi- ^ model M of Ps is 
a stable model o/0{Pi : i G S} at state s iff: 

M = least{[P — Reject{s, M)] U Default{V, M)) 

It is clear from the definitions that stable models of dynamic programs are 
a generalization of stable models of generalized and normal programs, i.e. if the 
dynamic program consists of a single generalized (resp. normal) program then its 
semantics is the same as that of the stable models of generalized (resp. normal) 
programs. It is also shown in [1] that dynamic logic programs generalize the 
interpretation updates of [11]. 

In [1] a transformational semantics for dynamic programs is also presented. 
According to this equivalent definition, a sequence of programs is translated into 
a single generalized program (with one new argument added to all predicates) 
whose stable models are in one-to-one correspondence with the stable models of 
the dynamic program. This transformational semantics is the basis of an existing 
implementation of dynamic logic programming^. 



3 Preferred Stable Models 

In this section we recall the preferences approach of [5], and set forth a def- 
inition of preferred stable models for generalized logic programs (rather than 

^ Publicly available from: http://centria.di.fct.unl.pt/~jja/updates/ 
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for extended logic programs as in [5]) in a form suitable for integration with 
the above described updates. In [5], logic programs are supplied with priority 
information, given in the form of a strict partial ordering on program rules^. 

Definition 7 (Prioritized generalized logic program). Let P he a general- 
ized program and let < be a strict partial order over the rules of P, where r\ < V2 
means r\ is preferred to r2- Then {P, <) is a prioritized generalized program^ . 

Intuitively, the priority information is used to prefer among the various stable 
models of the program. The question here is what stable models to prefer in the 
face of a given priority relation among rules. To respond to this question, the 
authors in [5] start by formulating two principles all preference system should 
satisfy. The first {Principle I), is envisaged as a minimal requirement for pref- 
erence handling, and states that if a stable model Mi is generated by a set of 
rules® i? U {ri}, and another stable model M2 is generated by i? U {r2}, where 
ri,r2 ^ R, then, if r\ < V2, M2 cannot be preferred. The second {Principle 
II), captures a notion of relevance. It affirms that adding a rule which is not 
applicable in a preferred model can never render this model unpreferred. 

With these two principles in mind, [5] defines a criterion for preferring among 
stable models, given a priority relation on rules. Their basic idea is that a stable 
model M can only be preferred if, for each rule in the program, whenever its 
(positive) prerequisites are true in M and its head is false in M, then there must 
be some not A in its body which is false in M, and there is a more preferred rule 
generating A. I.e. for a rule with true prerequisites not to be applied, there must 
be a more prioritary rule preventing its application. 

Before presenting our equivalent definition of preferred stable models, let us 
first briefly review the formal definition of preferred answer sets of [5] specialized 
for the case where the program is ground. A preferred answer-set is a model 
of the program simultaneously satisfying two conditions: it must be a stable 
model (i.e. be a fixpoint of the P Gelfond-Lifschitz operator); it must satisfy a 
fixpoint equation which, intuitively, guarantees that the rules are being applied 
in observance of the partial order, i.e. that the criterion described above is met. 

Adopting the view that rules are applied one at a time, a partial ordering on 
rules should be viewed as a representative of all its possible refinements into to- 
tal orderings. These, defined in [5], are dubbed full prioritizations of prioritized 
programs. A program is said fully prioritized if it coincides with its single full 
prioritization. The fixpoint construction guaranteeing that rules of a fully prior- 
itized program are applied in the correct order is carried out in two steps. First, 
all (positive) atoms in the body are preprocessed away on the basis of their truth 

® For a comparison with approaches ordering atoms rather than rules see [5]. 

^ Note that, in contradistinction to [5], our priority relation is defined for ground 
programs. To define the relation directly on non-ground programs, the methodology 
given in [5], using well-orderings, could just as well be applied to our case. However, 
for simplicity, we will not consider it in this paper. 

® The set of rules that generate a stable model is made up of all the rules in the 
program whose body is true in the stable model. 
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value in the model. More precisely, this so called dual Gelfond-Lifschitz reduc- 
tion ^TZ is obtained from TZ by first deleting every rule having a prerequisite A 
such that A ^ M, and then removing from the remaining rules all prerequisites. 
All bodies of rules now exhibit only default literals. 

The correct order of applying rules is then checked in the thus obtained prere- 
quisite-free program. Informally, this is achieved by, following rule order, adding 
the heads of those rules that are not defeated by a rule having higher priority 
(whose head has been added). Formally: 

Definition 8 (Defeating of rules). A rule r is defeated by a set of literals S 
ijj 3 not A G body{r) : A G S. 



Definition 9 {Cn operator [5]). Let TZ = {P,<) be a prerequisite-free fully 
prioritized logic program, and let M be a set of ground literals. Cn{M) is the least 
fixpoint of the sequence Sa (where a ranges over the rules of the fully prioritized 
P, according to their (total) ordering): 

{ U/3<a 5'/3 if ra is defeated by Sp or 

ra is defeated by M and header a) G M; 
U/3<a U {header a)} otherwise 



Definition 10 (Preferred Answer Set). Let TZ = {P, <) be a prioritized logic 
program and let TZf = (P, </) be a full prioritization ofTZ. A model M of P is 
a preferred answer set ofTZ iff M = Pp{M) and M = Cm-p^{M). 

As motivated in the Introduction, and in order to facilitate the capture of 
both preferences and updates in one single framework, it is our goal in this 
section to devise a declarative semantics for prioritized generalized programs 
based on the removal of (less preferred) rules, inasmuch our update framework 
hinges likewise on the removal of rules; this maneuver is crucial for fusing the 
two. Moreover, we require this semantics to coincide with the one in [5] on normal 
programs. The main issue in so doing rests in determining criteria for which rules 
to remove, in order to obtain exactly the same semantics. Before presenting 
its definition, we begin by reporting, with small but illustrative examples, on 
the problems involved in finding them®. Like in [5], we start with the case of 
prerequisite-free programs. 

Example 2. Consider the program: (1) a ^ noth (2) b^nota, where 
rule (1) is preferred over rule (2). Its stable models are Mi = {a} and M 2 = {b}, 
the preferred one being Mi. Intuitively, since (1) < (2) and the head of rule (1) 
defeats (2), in order to obtain the preferred stable model, one should remove 
rule (2). Indeed, Mi is the single stable model of the program after the excision. 

® This account is important here because for lack of space, the proof of equivalence 
with [5] does not fit. The problems depicted below form the core issues dealt with 
by the proof. 
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Mark that the reasoning brought out in this example concurs with the defi- 
nition of the C-jz operator. According to it, the head of a rule is not added if the 
rule is defeated by the previously constructed set. But this set is formed precisely 
by the heads of the more preferred rules. Instead of not adding the head to the 
set, the same effect can be achieved by removing the rule, i.e. by removing all 
rules defeated by the head of a more preferred rule, which has not itself in turn 
been removed. 

Example 3. Consider now: (1) b ^ note (2) c ^ notd (3) a ^ noth 
(4) b <— not a, where a rule (i) is preferred over rule (j) iff f < j. Its stable 
models are Mi = {a,c} and M 2 = {b,c}. According to Principle I above, since 
Ml is generated by rules (2) and (3), and M 2 by rules (2) and (4), M 2 should 
not be preferred. But, resorting to the reasoning explained above, rule (3) is 
removed (as it is defeated by the head of rule (1)), and the only stable model of 
the resulting program becomes M 2 . Why shouldn’t rule (1) remove (3)? Because 
rule (1) is defeated in whichever model. This is in line with Definition 9 (2nd 
line of So) where heads of rules true in the model, whose body is defeated by the 
model, are not added to the set. Accordingly, given some model, all such rules 
are removed. Hereafter, we refer to them as “unsupported rules” . 

Consequently, in model M 2 rule (1) is removed, as well as rule (4) (the latter 
is defeated by the head of the more preferred and non-removed rule (3)). And 
M 2 is not a stable model of the program after those rules are withdrawn. 

The two above criteria for deleting rules (viz. deleting less preferred rules 
defeated by the head of some more preferred rule, and deleting “unsupported 
rules”) concur with the definition of the Cji operator. However, as evidenced by 
the example below, they are not enough. 

Example 4- Consider now: (1) a ^ noth (2) b^notc (1)<(2), 

whose only stable model is M = {6}, which according to [5] is not preferred. This 
is so because rule (1) is neither unsupported (a is not true in M) nor defeated 
by a more preferred rule, so a is added in the construction of C-jz{M), and M 
cannot thereafter be a fixpoint of the operator. However, using only the two 
above criteria none of these two rules is eliminated, and M would be preferred. 

To obtain the effect achieved by [5], one must guarantee that, in spite of rule 
removal, a is enforced in the preferred models of the reduced program. This is 
accomplished by removing any rules less preferred than the one for a, which, if 
otherwise were not removed, would cause a not to be in the preferred models. In 
other words, one is required to remove all rules having true body in the model, 
whose heads defeat a more preferred rule. Mark well that if the body of the 
less preferred rule is not actually true in the model, then the defeating is only a 
potential but not effective one, and the rule must not be eliminated. Indeed, its 
preservation will permit it to defeat, and cause to remove, rules less preferred 
than itself even if they attack it. When considering programs with prerequisites, 
one must further insist that the more preferred rule is not deleted by the dual 
reduct transformation. This is ensured by verifying that the positive part of the 
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body of the more preferred rule is actually true in the model. A similar reasoning 
applies to the other two criteria explained above. These three criteria suffice for 
formalizing, in Definition 12, the set of unpreferred rules. 

Definition 11 (Unsupported rules). Let M he a model of P. Then: 
Unsup{P, M) = {r £ P : M \= {head{r)} U bodypos{r) A M ^ bodyneg{r)} 



Definition 12 (Unpreferred rules). Let M he a model of P. The set of unpre- 
ferred rules, Unpref{P,M), is the least set of rules that includes Unsup{P,M), 
and every r in P such that: 

3r' £ P — Unpref{P, M) : r' < r f\ M \= bodypos{r') A 

[not head{r') £ bodyneg(j") V (nothead(r) £ bodyneg(j"') A M \= body(r)) ] 

Lack of space prevents us from showing that such a least set always exists. 
Indeed, it can be contracted by iterating the definition of unpreferred rule ac- 
cording to rules’ ordering, starting from the set of unsupported rules. 

For programs with positive atoms in rule bodies, the effect of the dual re- 
duction operation of [5] is obtained by adding to the program facts not A for 
every A with no rule in the original program with true body in the model, and 
thereafter computing the least model. 

Definition 13 (Preferred Stable Models). A model M of program P is a 
preferred stable model of the prioritized generalized program {P, <) iff: 

M = least{[P — Unpref{P, M)] U Default{P, M)) 

This guarantees that the preferred models obtained after removing all un- 
preferred rules are also stable models of P, and so only one fixpoint equation is 
needed in this definition, as desired. Verily: 



Proposition 1. Let M he a preferred stable model of {P, <). Then M is also a 
stable model of P, i.e. M = least{P U Default{P, M)). 

Now, as expected, as this was one of our primary goals for the definition of 
preferred stable models, in programs where both the preferred answer sets of [5] 
and our preferred stable models can be applied (i.e. in normal programs), their 
results coincide. For an extensive study of the properties of preferred answer-sets, 
its intuitions, examples, and comparisons with related approaches see [5]. 

Theorem 1. Let P he a ground normal logic program, and let < he a strict 
partial order over the rules of P. M is a preferred stable model of (P,<) iff M 
is a preferred answer-set of (P, <) in the sense of Brewka and Eiter [5]. 
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4 Updating Logic Programs with Preferences 

Having separately defined both updates and preferences in an analogous way, in 
this section we combine both concepts into an unified framework. Moreover, as 
motivated in the Introduction, the combined framework must also allow for the 
updating of the priority relation itself. 

Leaving, for now, the issue of updating the priority relation, we must consider 
sequences of generalized programs Pi 0 ... 0 , viewed as sequences of updates 

of an original program, plus some priority relation among rules. One first basic 
question is in order: where to define the priority relation? Among the rules for 
the same program? Or among rules in the union of all programs in the sequence? 
More formally, should there be a strict partial order <i for each of the Pi in the 
sequence, or should there be a single strict partial order < defined over the rules 
of Uies U? Clearly, the latter approach is more general than the former: it does 
not prevent limiting the priority relation to rules in the same Pi, while the former 
does prevent priority relations between rules from different P^s. Furthermore, the 
extra generality is useful. For instance, in the situation of Example 1, one may 
want to say at a given state that I go to the beach unless I go to the mountain, 
and later say that I go to the mountain unless I go to the beach, and establish a 
priority over these rules. Note that the rules were introduced at different update 
stages, and so the priority relation is to be established between rules of different 
PiS. Accordingly, in our framework we consider a single priority relation defined 
on the rules of IJjgg Pi, which can evolve as new rules are introduced. 

To cope with the possibility of updating the priority relation, it cannot be 
fixed. Rather it must be described in some language that allows for the possi- 
bility of its evolution, via updates. One such language is precisely DLP and, for 
uniformity, that is what is used in our framework. Thus, instead of a sequence 
of programs representing knowledge, we have a sequence of pairs: of programs 
representing knowledge, and of programs describing the priority relation among 
rules of the knowledge representation. In general, an update of the priority rela- 
tion may depend on some other predicate (e.g. in Example 1, I may want to say 
that, if I have to work, then I prefer the rule advising me to stay in the city). To 
permit this generality, we allow rules in programs describing the priority relation 
to refer to predicates defined in the programs that represent knowledge. 

Definition 14 (Dynamic Prioritized Programs). Let V = {Ps : s G S} be 

a dynamic logic program whose alphabet does not contain the strict partial order 
arity H predicate symbol <, and let TZ = {Rs : s G S} be another dynamic logic 
program whose alphabet contains at least the predicate symbol <, and whose sets 
of constants includes all the rules in the union of all Ps inV . Then ®{(Ps, Rs) '■ 
s G S} is a Dynamic Prioritized Program. 

Given the very deliberate definition forms of the semantics of preferences and 
of updates, it is not difficult to combine both in a single one, as per the above 
delineated framework. Given a model M of the last program in the sequence 
(or, in the general setting, of the program state we want to query), for testing 
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stability we have first to remove all the rejected rules according to updates, and 
then all the unpreferred rules according to preferences. Note, however, that if 
both sets of rules (rejected and unpreferred) were removed simultaneosly, then a 
rule which is rejected by an update, might serve for unprefering some other rule. 
This would lead to counterintuitive results. In fact, updates have precedence 
over preferences. If a previous rule is invalidated by a subsequently introduced 
rule, then the former should no longer be available in the preferences setting. 
Accordingly, the set of unpreferred rules must be determined on the basis of the 
program obtained after removing those rules rejected by any updates. In general, 
the union of all programs in the sequence may be inconsistent, and it would make 
no sense to apply preferences to this inconsistent set of rules; updates are applied 
first (by rejecting rules) and allow you to come up with a consistent set of rules; 
preferences then intervene to choose among the various models of that consistent 
set of rules. 

Since the priority relation is itself defined by the dynamic prioritized program, 
models must also take into account the < predicate, i.e. one has to entertain mod- 
els of the union of with i?„. Moreover, in the definition of unpreferred rules, 
the priority relation must be checked in regard to the model under consideration: 

Definition 15 (Unpreferred rnles). Unpref{P, M) is the least set of rules 
including Unsup{P,M) and rules r in P such that: 

3r'e P — Unpref{P, M) :M^r'<rAM|= hodyposir') A 

\nothead{r') e bodyneg{r) V {not header) G bodyneg{r') /\ M \= body{r)) ] 

In the definition of preferred stable model, it is crucial that the priority re- 
lation be a strict partial order (i.e. irreflexive and transitive). In our framework, 
since the user can write any rules for describing predicate <, it may well happen 
that its extention be a relation not complying with those properties. The defi- 
nition of the semantics must prevent this being the case, i.e. must only consider 
models where the extension of predicate < is indeed a strict partial order. Thus: 

Definition 16 (Preferred Stable Models at state s). Let ®{(Pi,i?i) : 
i G S'} he a Dynamic Prioritized Logic Program, let s G S, and let VTZ = 
Ui<s(Pi U Ri). A model M of PsU Rs is a preferred stable model at state s iff: 

- Wr : {r < r) ^ M and Vri, r 2 , rs : {r\ < r 2 , r 2 < rs} C M ^ {n < rs) G M 

— M = least{ [VTZ — Reject{s, M) — U npref{VTZ — Reject{s, M), M)] 

U Default{VTZ, M) ) 

This definition makes it clear that dynamic prioritized programs generalize 
both dynamic logic programs and prioritized logic programs. In fact, if all the 
RiS are empty, then Definition 16 is clearly equivalent to Definition 6. And if 
there is a single pair (P, R) in the sequence, then Definition 16 is equivalent 
to Definition 13, the priority relation of the prioritized program being the least 
model of R. We now illustrate the overall framework with two examples: 
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Example 5. The first 4 stages in the “sad story” of Example 1 can be modelled 
by the dynamic prioritized program (Pi , Pi ) 0 ... 0 (P4, P4) (where, for simplic- 
ity, we adopt unique numbers for rules, instead of the rules themselves in the 
priority relation, and where c stands for “living in the city” , mt for “settling on 
a mountain” , b for “living by the beach” , t for “travelling” , wk for “work” , vac 
for “vacations” , and mo for “possessing money” ) : 



Pi 


:(1) 


c ^ 


not mt, noth, not t 


Pi 


: X <Y ^ 


Y < Z, 




(2) 


wk 




P2 : 


:(1) 


< 


( 4 ) 


^ wk 




( 3 ) 


vac 


^ not wk 




(1) 


< 


( 5 ) 


^ wk 


P2 


:( 4 ) 


mt • 


not c, not b, not t, mo 




(1) 


< 


(6) 


^ wk 




( 5 ) 


b^ 


not mt, not c, not t, mo 


P3: 


:( 4 ) 


< 


(6) 


^ vac 




(6) 


t ^ 


not mt, not b, not c, mo 




( 5 ) 


< 


(6) 


<— vac 




( 7 ) 


mo 






(6) 


< 


(1) 


<— vac 


P3 


:(8) 


not 


wk <— 












P4 




{} 




P4 : 


:( 4 ) 


< 


( 5 ) 





For example, the only preferred stable model at state 4 is: 

{mt, vac, mo, (4) < (5), (4) < (6), (4) < (1), (5) < (6), (5) < (1), (6) < (1)} 

and the preferred stable models at state 3 are two: 

[mt, vac, mo, (4) < (6), (4) < (1), (5) < (6), (5) < (1), (6) < (1)} 

{b, vac, mo, (4) < (6), (4) < (1), (5) < (6), (5) < (1), (6) < (1)} 

Note in this example how the inertia of the transitivity rule (added in Pi) 
enforces transitivity on the priority relation in all the subsequent states. 



Example 6. Consider the following situation (adapted from an example of qual- 
itative decision making in [5]). You want to buy a car and, for that purpose, you 
have collected the following information about different types of caxs: safe(volvo), 
fast(chevrolet), expensive(chevrolet), saf e{chevrolet) , and fast{porsche). 
Let’s assume you like fast cars, and your budget does not allow you to purchase 
an expensive one. Moreover, you cannot afford more than one car. 

This situation can be modelled by P\ which, besides the facts above, has^: 

(1) notbuy{X) ^ avoid(X) 

(2) avoid{X) ^ not buy {X), expen sive{X) 

(3) buy{X) ^ notavoid(X), fast{X) 

(4) avoid{Y) ^ fast{X),buy{X),Y yf X 

See [5] for an explanation on how to come up with this program given the 
described situation, in particular the need for rule (4) in modelling the fact 
that you may not buy two cars®. Since there is not much you can do with your 

^ Rules with variables simply stand for their (finite) ground instances. 

® In fact, the coding of this piece of knowledge by itself is not related to npdates, 
and the rnles above are jnst those present in [5] where ~^buy{X) is here replaced by 
avoid(X), and (1) encodes the relation between these two predicates. 
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restricted budget, rule (2) has priority over rules (3) and (4). So R\ = {(2) < 
(3),(2)<(4)}. 

The reader can check that the only preferred stable model of in- 

cludes {buy{porsche),avoid{volvo),avoid{chevrolet)}, besides the facts and the 
priority relation, and you should buy the Porsche. 

Now your “significant other” insists that you should consider buying a safe 
car. Moreover, as a gentleperson, you ascribe priority to your partner’s sugges- 
tion. To assimilate this new information you update your knowledge with: 

P 2 : (5) buy{X) ^ not avoid{X) , safe{X) 

(6) avoid{Y) ^ safe{X),buy{X),Y 

and i?2 = {(5) < (3), (5) < (4), (6) < (3), (6) < (4), (2) < (5), (2) < (6)}. Now 
the only preferred stable model (at state 2) includes buy{volvo), avoid{porsche) 
and avoid{chevrolet), and you should buy the Volvo instead. 

Now suppose you discover Volvos are out of stock, and so you cannot buy 
one so soon. For that you add P3 = {notbuy{volvo)}, plus an empty R 3 . With 
this new update, rule (5) is now rejected, and the only stable model at state 3 
this time includes {buy{porsche),avoid{volvo),avoid{chevrolet)}. 

5 Conclusions and Future Work 

We have motivated the need for coupling preferences with updates, and shown 
how to accomplish it within the logic programming paradigm. We did so by 
devising a unified framework that combines the hitherto separate approaches to 
each aspect, and allows for preferences themselves to be updated. The framework 
coincides with [5] when a single program is given in the sequence, and with [1] 
when the preference relation is empty. Thus, for comparisons of this framework 
with others with preferences alone see [5], and for that with others with updates 
alone see [1]. 

To the best of our knowledge, [15] is the only work considering some combi- 
nation of preferences and updates. However, the generality of the combination 
of both reasoning mechanisms in [15] is far from that of the present paper. In 
fact, [15] ’s concern is with updates alone, and mainly considers the process of 
updating one program by another program, with mechanisms similar to those 
of [1] (i.e. removing rules from the initial program which “somehow” contradict 
rules from the update program, and retaining all others by inertia). Addition- 
ally, at the end, all rules from the update program are given preference over all 
retained rules of the initial program. No other preference ordering is considered 
there. And, as argued in the Introduction, updates alone do not necessarily force 
such preferences. In our framework, the user can state that more recent rules are 
preferred over older ones, but is also free to state differently. Moreover, in our 
framework the preference relation itself can be updated. The greater generality 
of our approach stems as well from our usage of [1] as the basis for updates. In 
fact, note that [I] considers arbitrary sequences of updates whereas [15] simply 
considers the update of one program by another. In [15] some semantical prop- 
erties of their system are investigated. However, all such properties address only 
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updating, and not some combination of it with preferences. It remains to be 
studied what generic principles any system combining preferences and updates 
(not necessarily in logic programming) should comply with. Those principles 
would help the comparison with [15] and possible other systems. Such generic 
study, and the verification of the principles in our framework, is work we are 
now developing. 

Several other topics cry out for subsequent development. First, we are work- 
ing on a transformational semantics of preferences into logic programs, to be 
coupled with the extant aforementioned one for updates. This will readily pro- 
pitiate an implementation of the overall framework, as well as serve as a basis 
for the study of its computational properties. 

An outstanding issue, on which some effort needs deploying, concerns how 
to automatically ensure irreflexivity and transitivity of the partial order, as it 
is being updated. For the moment this responsibility is wholly relegated to the 
updater. As it stands, in case of infringement there will simply be no model, 
as per Definition 16. It is in our plans to study the adequacy of the update 
mechanism on rules for predicate < so as to automatically guarantee irreflexivity 
and transitivity. In this respect, note in Example 5, how transitivity is always 
guaranteed by adding one rule to the initial program. 

Finally, we also intend to explore application areas such as e-commerce, legal 
reasoning, and rational agents. They will certainly provide valuable opportunities 
and hints for the evolution of the topics broached in this paper. 
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Abstract. In this paper we show how several different semantics for be- 
lief update can be expressed in a framework for reasoning about actions. 
This framework can therefore be considered as a common core of all these 
update formalisms, thus making it clear what they have in common. This 
framework also allows expressing scenarios that are problematic for the 
classical formalization of belief update. 



1 Introduction 

Belief update and reasoning about actions are two well studied areas of research 
about the evolution of knowledge over time. The similarities between these two 
fields have already been pointed out by some researchers: for example del Val 
and Shoham [4] use a theory of action to derive a semantics for belief update; Li 
and Pereira [8] use a Ginsberg- like semantics for updating a theory of actions. 

In this paper we present a very simple action description language [6] with 
narratives that allows expressing several different update semantics. The basic 
principles of this language has already been investigated in the literature. Indeed, 
the basic semantics of this language can be seen as a proper restriction of the 
language C by Baral et al. [1]. What is new in this paper is not the language 
itself, but rather the way it is able to express update semantics. 

To introduce the language, we consider an example similar to the evergreen 
Yale Shooting Problem. 



initially Loaded 
initially Alive 
Alive holds at 3 
Shoot happens at 2 
Unload causes ^Loaded 
Shoot causes ^ Alive if Loaded 

Short explanation of the syntax: at time 0 Fred is alive, and the gun is 
loaded. Fred is still alive at time 3. This is the meaning of the initially and 
holds at propositions. The last two propositions specify the effect of actions: the 
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action Unload causes the gun to be loaded no longer, while the action Shoot 
causes Fred to die, if the gun is loaded. 

According to the original semantics of the basic action description language 
A [6], this domain description is inconsistent. This can be intuitively explained 
as follows: at time 0 the gun is loaded. Since nothing happens between time 0 
and 2, the gun remains loaded. As a result, the effect of shooting at Fred at time 
2 causes him to die, since the gun is still loaded. 

Such inconsistent scenarios are very common in the field of belief revision 
and update. Suppose for example we have loaded the gun at time 0. Then, we 
have done nothing modifying the domain of interest (e.g. we go out for a walk, 
we have a nap, we just do nothing at all, etc.) When we shoot the gun, Fred does 
not die. This is surprising, since we expected the gun to be still loaded. However, 
it is very easy to find an explanation: someone unloaded the gun while we was 
not looking at it. Such conclusion can be drawn assuming that some actions may 
take place at some time points, and this is initially not known. 

In languages with narratives, such that the language AU introduced in this 
paper, such a deduction is possible. Note that it is not only a matter of find- 
ing an explanation of already known facts. For example, we can conclude that 
-^Loaded holds at 2 from the domain description above. Such an inference is 
clearly impossible in the basic action description language A. 

The example describes a prototypical scenario of belief update: we have a set 
of facts which are known to holds at a certain time point (e.g. the gun is loaded 
and Fred is alive at time 0). In a subsequent time point something is observed 
(e.g. Fred is alive at time 3). The possible inconsistency between the facts and 
the observation is explained as due to changes happened in the world. In this 
paper, the assumption is that all changes are caused by actions. 

The formalization of change given in belief update is very simple. If T is a 
set of known facts, and P is an observation, T* P denotes the result of updating 
T with P, that is, our knowledge after the observation of P. The use of this 
notation seemed the natural choice to the first researchers in the field, since 
what we want to formalize is indeed the update of T with P. 

This notation is very simple, but sometimes it does not allow to express 
enough information. The example of the gun contains information that cannot 
be formalized using the star notation. For example, there is no way to express the 
fact that it is impossible that Fred becomes alive, once it is dead. Such informa- 
tion cannot be represented using the notation T * P, since the only information 
expressed in this way is the old set of facts T and the observation P. Another 
problem is the impossibility of deciding what is true in time points before the 
update. In the example, Loaded is false at time 2. However, T * P only expresses 
the result of the update, that is, what is known at the time of the observation 
(in this case, at time 3). As a result, there is no way to even ask what is true 
at time 1, or 2, etc. Finally, there are problems in formalizing the process of 
iterated update. For example, (T * Pi) * P 2 is different from the intuitive result 
of incorporating two observations Pi and P 2 (for an explanation of why, we refer 
the reader to the borrowed car example [5]). 
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All these issues have already been pointed out by researchers in the field, for 
example Boutilier [2, 3] and Li and Pereira [8]. However, most of these formalisms 
employ an ad-hoc syntax and semantics. The framework introduced in this paper 
allows for formalizing all those forms of update. The semantics of the language 
generalizes many semantics given for belief update. 

The benefits of AU are twofold: it is at the same time a useful extension of 
action theories with narratives, and it allows an easy and intuitive formalization 
(in a standard way) of theories of belief update. 

The paper is organized as follows: in the next section we describe the syntax 
and the semantics of the language JJU. The syntax of MA is similar to that 
of action description languages with narratives. As a result, we can define a 
“classical” semantics for it, as well as a semantics that formalizes actions that 
are not known to be happened. We prove that many belief update semantics can 
be captured this way. Finally, we compare our approach with other ones dealing 
with updates and action theories, and discuss possible extensions of this work. 

2 The Language AU. 

2.1 Syntax 

The alphabet of the language is composed by three mutually disjoint sets: the 
set of actions, the set of fiuents, and the set of time points. In this paper we 
assume that the set of time points is the set of non-negative integers. 

A fluent literal is a fluent possibly preceded by the negation symbol A 
fluent expression is a propositional formula over the alphabet of fiuents. Thus, 
all the fluent literals are also fluent expressions, and if E\ and E 2 are fluent 
expressions, so are Ei A E 2 , EiV E 2 , and ^Ei. 

A domain description is composed of three parts: behavioral, historical, and 
actual. If D is a domain description then Db, Dh, and Da are its behavioral, 
historical, and actual parts, respectively. 

Behavioral Part. Is the set of effect propositions, and is the part of the do- 
main that specifies how the domain behaves in response to actions. An effect 
proposition is as follows: 



A causes F if Pi, ... , Pm 

where P is a fluent literal, Pi, ... , Pm are fluent expressions, and A is an action. 
The meaning is that the action A causes the fluent literal E to become true, if 
the fluent expressions Pi, . . . ,Pm are currently true. For this reason, the fluent 
expressions Pi, ... , Pm are called the preconditions of the proposition, and F is 
called the effect. 

Historical Part. Is the specification of the actions that are known to have 
been executed. A happens proposition is a statement of the form 



A happens at t 
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where A is an action and t is a time point. The meaning is clear: the action A 
is executed at time point t. 

Actual Part. Is the set of propositions that specify the status of a fluent at a 
certain time point. 



E after Ai] . . .] Am from t 

where if is a fluent expression, Ai; . . . ; Am are actions and t is a time point. 
The meaning is that the fluent expression E is true after executing the actions 
Aim . in sequence starting from the time point t. This propositions allows 

to specify both the status of a “real” time point, and the status of hypothetical 
situations. When m = 0 (i.e. no actions) the proposition is written E holds at t, 
its meaning being that the fluent expression E is true in the time point t. On 
the other hand, when t = 0, we write E after Ai] . . .] Am- What is the difference 
between propositions like E holds at t and E after Ai; . . . ; Am"l The first one 
refers to a specific time point t. The second one refers to a sequence of actions. 
It is possible that the actions executed from 0 are not the sequence Ai; . . . ; Am- 
If this is the case, E after Ai \ . . .] Am is a form of conditional knowledge: if the 
actions Aim..]Am were executed then E would be true. On the other hand, 
E holds at t refers to the real status of the world at a certain time point. 



2.2 Classical Semantics 

In this section we present the semantics of the language, according to the hy- 
pothesis that all the actions that are executed are known. 

A state is a set of fluent names. A fluent literal without negation F is true in 
the state a \i E & a, false otherwise. A fluent expression ~^E is true in cr if and 
only if E is false in a. A fluent expression Ei A E 2 is true in cr if both Ei and 
E 2 are true in cr. A fluent expression Ei V E 2 is true in a if either Ei is true in 
cr or E 2 is true in a. 

A transition function is a function from the set of pairs (A, cr), where A 
is an action and a a state, to the set of states. With 'P{A, a) we want to repre- 
sent the state obtained performing the action A in the state a. We abbreviate 
<!>{Am, . . . , <P{Ai,a ) . . .)) as <P{Ai ; . . . ; Am, cr). This is the state obtained 

after executing the sequence of actions Ai; . . .; Am in a. 

Let V^^(A,a) be the set of the fluent names F (i.e. positive fluent liter- 
als) such that there exists an effect proposition A causes A if Pi, ... , Pm in the 
behavioral part of the domain description D and P\, . . . ,Pm are true in cr. In- 
tuitively, {A, a) represents the set of fluents whose value must became true 
when the action A is performed in the state a. 

In a similar manner, (A, cr) is the set of fluents whose value must became 
false, and thus is defined as the set of fluent names F such that there exists an 
effect proposition A causes ~^F if Pi, ... , Pm in Pb and Pi, ... , Pm are true in 



cr. 




A Framework for Belief Update 365 



The transition function associated to a behavioral part Db is the (partial) 
function '1/db defined as 

i&n (A ct') = I if ^Db ^Bb = ^ 

^ i ( undefined otherwise 

We used the subscript Db here to stress the fact that the transition function 
of a domain description is determined by its behavioral part only. We assume 
that the transition function associated to a domain description D is always total. 
This can be verified in polynomial time. 

The sequence of actions associated to a time point t is defined as the sequence 
of actions Bi; . . . ; Bk that have been happened before t. Formally, given a set of 
happens propositions H, we define 



S{H, t) = Bi] . . ,;Bk such that 

1. {Bi happens at ti, . . . , Bk happens at tk} C H 

2. 0 < < t2 < ••• < tfc < f 

3. there is no other proposition C happens at t' 

in H such that 0 < t' < t 

S{H,t) is the sequence of actions that have took place in the time interval 
between the time points 0 and t. 

We define interpreted structures and models as follows. 

Definition 1. An interpreted structure is a 3-tuple M = where cto 

is a state, <P is a transition function, and H is a set of happens at propositions. 



Definition 2. An interpreted structure M = (ao,<P,H) is a model of a domain 
description D = Db U Dh U Da (written M \= D) if and only if 

1. <P = 'I'db 

2. H = Dh 

3. for each pair of actions A\ and A 2 , and each time point t, it does not hold 
Ai happens at t G H and A 2 happens at t G H (non-concurrency) . 

4 . for each proposition E after Ai; . . . ; Am from t in Da, the fluent expression 
E is true in the state <P{S{E{, t); Ai ; . . . ; Am, co). 

A domain description is consistent if it has models. A domain description 
entails a proposition E after Ai;...;Am from t if and only if, for each M = 
{ao,<P,H) such that M \= D, the fluent expression E is true in the state 
f); Ai; . . . ; Am, CTo). If this is the case, we write D \= E after Ai;...; 
Am from t. 
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2.3 Update Semantics 

The semantics of the previous section does not take into account actions that 
happened, but of which we have no knowledge. For example, the domain de- 
scription 

D = {A causes F, holds at 0, F holds at 1} 

is not consistent. This is because the value of a fluent remains unchanged if there 
is no action modifying it. Since there is no happens proposition specifying that 
an action happened in the time point 0, the value of the fluent F’ at 1 should be 
the same of that at 0. Instead, the truth value of the fluent is changed. 

Intuitively, it is clear that the action A happens at 0, and this causes the fluent 
F to become true. However, such an inference is not allowed in the semantics 
of the previous section, which assumes that the only actions that have been 
happened are those specified in the domain description. 

In this section we present a semantics that allows the inference of statements 
about actions which are not known to be happened. First of all, we define a 
model with abduced actions as follows. 

Definition 3. An interpreted structure M = (cto,F, iF) is a model with abduced 
actions for the domain description D = Db U Dh U Da (written M \=a D) if 
and only if: 

1. <P = ^Db 

2. Dh QH 

3. for each pair of different actions Ai and A 2 , and each time point t, it does 

not hold Ai happens at t G F[ and A 2 happens at t G H (non-concurrency) . 

4 . for each proposition E after Hi; ... ; A^ from t in Da, the fluent expression 

E is true in the state <P{S{F{, t); Hi; . . . ; Am, cto). 

The only difference between this definition and the one given in the previous 
section is the fact that H can be a superset of Dh, rather than Dh itself. Of 
course, this way arbitrarily large sets of happens propositions are allowed to be 
part of F[. To this extent, a definition of minimality is needed. We assume that 
there is an ordering between interpreted structures. 

Definition 4. H minimal model M of a domain description D is a minimal 
(w.r.t. A) model with abduced actions of D. 

Thus, “minimal model” is indeed a shorthand. We define a domain de- 
scription D to be consistent if it has at least one minimal model. A domain 
description D entails a proposition E after Hi;...;Hm from t if and only if, 
for each minimal model M of D, the fluent expression E is true in the state 
<P{S{E[, f); Hi; . . . ; Am, <Jo)- If this is the case, we write: 

D \=A E after Hi; ... ; Am from t 

The last point to be defined is the ordering The choice of ^ depends on 
the knowledge about the domain. A general principle is that a model with less 
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happens statements should be preferred (i.e. should be lower than, according 
to over models with more happens statements. This leads to the following 
definition. 

Definition 5. The standard ordering :<s is defined as: 



{ fJo = (Tl 
Wo = Wi 
HoQHi 

Using this specific ordering, AU can be seen as a fragment of the logic C 
by Baral et al. [1]. What makes MA interesting is the fact that, using different 
orderings, it allows for expressing different update semantics, thus characterizing 
a number of natural processes of abducting execution of actions. 

The entailment relation \=a obtained from the standard ordering <s can be 
used to express the scenario of the example described in the introduction. Indeed, 
one can prove that the domain description entails for example -^Loaded holds at 2, 
which is intuitively the only possible reason of why Fred is still alive. Note that 
it is also possible to formalize the similar scenario in which we know that noth- 
ing happens between time 0 and 2: just add an action TVop, without effects, and 
two happens propositions Nop happens at 0 and Nop happens at 1 to the domain 
description. This new domain description is inconsistent: in this case, this is the 
intuitive outcome. 



3 Belief Update Using JKU 

In this section we show how several definitions of belief update can be formalized 
in a domain of actions using the language AU. The motivation for doing so is 
twofold. The first is that this formalization allows for a new interpretation of 
the definitions of update. For example, Winslett’s update can be expressed by 
introducing an action that change the value of a variable, and minimizing the 
set of actions happened. 

Moreover, by giving definitions of the ordering A, we solve the problem of 
not complete specification of the entailment relation \=a- Indeed, the ordering 
defined could be used for domain descriptions different from those given from 
the formalization of update. 

We consider the following update definitions: Winslett’s update [14], Katsuno 
and Mendelzon’s updates [7], and Boutilier’s abduction-based update [2]. We do 
not consider Boutilier’s event based update [3] due to the lack of space, but this 
update can be expressed in the formalism. 

We use the following notations: if P is a propositional formula, then Mod{P) 
is the set of its models. Conversely, if A is a set of models, then Form{A) is a 
propositional formula whose set of models is A. Thus, Form is a multi-valued 
function, since there are many formulas sharing the same set of models. This is 
not a problem in this work. 
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3.1 Winslett’s Update 

Consider a propositional formula T representing the state of the world. This 
information is assumed to be correct, but not (necessarily) complete. When a 
change in the world occurs, this description of the world must be modified. The 
assumption behind belief update is that what we know about the change is a 
propositional formula P that is true in the new situation. Winslett’s approach 
is model-based, that is, the result of the update T P is defined in terms of 
the sets of models of T and P. 

The underlying assumption in belief revision and update is that of minimal 
change: the knowledge base T should be changed as little as possible, in the 
process of incorporation of the update P. 

Winslett’s update [14] operates on a model by model base. Let / be an 
interpretation, and let </ be the ordering on interpretations defined as 

J<iZ iff Diff{I, J) C Diff{I, Z) 

where Diff{I, J) is the set of variable on which I and J disagree. Intuitively, 
J <i Z means that, since J and / have more literals assigned to the same truth 
value than Z and I, the interpretation J must be considered to be closer to / 
that Z. 

The update of the k.b. T when a new formula P becomes true after a change 
is defined considering each model of T separately. 

Mod{T P) = [J Tohi{Mod{P), <i)) 

lGMod(T) 

We show that Winslett’s update can be easily expressed in our framework. 
Let X be the alphabet of T and P. We define a domain description as follows. 
The set of fluents is the set of variables X. The intuitive explanation is: the set of 
fluent is the set of facts that may change over time, and this is also the meaning 
of the fluents in reasoning about actions. For each variable Xi there is an actions 
Ai. This action formalizes the change of value of the variable Xi between time 
points. 

The domain description is built as follows. For each variable Xi there are two 
effect propositions: 

Db = {Ai causes Xi if ~^Xi, Ai causes ^Xi if Xi} 

XiGX 

The historical part of the domain is empty: Dh = 0 . Let n = jXj, that is, 
the number of variables. The actual part of the domain description is composed 
of two propositions: 



Da = {T holds at 0, P holds at n} 

Thus, D = Db U Da- This formalization is a very intuitive one: the fluents 
are facts, and each action changes the value of a fact. This definition captures 
Winslett’s semantics of update. 
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Theorem 1. Let D be the domain description corresponding to T and P. Then, 
for each propositional formula Q over the alphabet X , it holds T P \= Q if 
and only if D \=a Q holds at n (using the standard ordering d:s)- 

P is assumed to hold at time n because we do not allow concurrent action. 

3.2 Katsuno and Mendelzon’s Update 

Katsuno and Mendelzon [7] defined a family of updates, rather than a specific 
operator. They also proved that Winslett’s operator is a sub-case of their defi- 
nition. 

Let O = {</ I / is an interpretation} be a family of partial orderings over the 
set of the interpretations, one for each interpretation I. In other words, for each 
interpretation / there is a partial ordering </ over the set of the interpretations. 
An interpretation / represents a complete description of the world. J <i Z 
means that the situation represented by the interpretation J is considered more 
plausible than the situation of Z. As a result, assuming that there has been a 
transition from I to J requires less change than the change from / to Z. Thus, 
assuming that I represents the current state, the result of the update should be: 

Mod{Form{I) *km P) = min(Mo<i(P), </) 

If the current k.b. is not composed of a single interpretation, this must be 
done for each I S Mod{T): 

Mod{T *km P) = [J min(Mod(P), </) 

lGMod{T) 

Note that Katsuno and Mendelzon define a set of update operators rather 
than a single one: indeed, each family of orderings define a specific KM operator. 
As a result, in order to specify an actual update, a family of orderings must be 
defined. 

There is a simple way to capture and Katsuno and Mendelzon’s update in our 
framework. Given a family of orderings (one for each interpretation) we define 
the domain description as the one given in the previous section. The ordering 
used is defined as follows. 

Definition 6. Given a family of partial ordering O = {</}, one for each 
interpretation I, we define an ordering over interpreted structures :<km as 
(ao,<Po,Ho) <km (cri,^i,i7i) if and only if 

1 . (Jo = (Ji. 

2. T'o = T>i. 

3. <Po{S{Ho,n),ao) <<jo <Pi{S{Hi,n),ai). 

Note that there is an ordering :<km for each family of orderings over the 
interpretations. Thus, the formally correct notation should be :<o, but we use 
diKM for simplicity. The following theorem shows that we are indeed formalizing 
the Katsuno and Mendelzon updates. 
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Theorem 2. For each Katsuno and Mendelzon update, and for each 3-tuple of 
propositional formulas T, P, and Q, it holds T * P \= Q if and only if D \=a 
Q holds at n, using the ordering :<km as in Definition 6. 

3.3 Abduction-Based Update 

The rationale of the abduction-based update [3] is that the events that change 
the world can be modeled by an abductive semantics. Some of these events may 
be more plausible than others. In order to explain the change, we choose only 
the ones we consider to be more plausible. 

Since this update requires the specification of the outcome of events, and their 
plausibility, the current knowledge base T and the update P do not suffice to 
evaluate the updated k.b.. This kind of updates, in which some extra information 
is required is called update schema. It can be viewed as a family of updates, one of 
each set of events and their plausibility. Giving the events and their plausibility 
is equivalent to selecting a specific update of the family. 

We now give the formal definition of the update. A more detailed explana- 
tion can be found in the paper where this update is introduced [3]. In order to 
explain the changes, we have a set of events E. Each event e is a function from 
interpretations to sets of interpretations. Thus, for each interpretation /, e(/) 
is a set of interpretations. The meaning of J G e(/) is that the possible world 
represented by the interpretation J is one of the possible outcomes of the event 
e, if this event occur in the world represented by the interpretation I. An event 
e is said to be deterministic if e{I) is always composed of a single interpretation. 

As seen in the informal explanation above, not all the events are considered 
equally plausible. To represent the relative plausibility of events we have a family 
of preorders O = {</ | I G AI}, one for each interpretation I. When e <i s the 
event e is considered more likely to happen that s, in the world represented by 
the interpretation I. We denote by e </ s the fact that e is strictly more likely 
than s; formally, that e <i s but not s </ e. 

Let T be the current k.b. and P the update. The set of explanations of P 
is the set of events whose occurrence can explain the fact that P is now true. 
There are two possible definitions. 

Definition 7. The set of weak explanations of P is 

Expl(7, P) = min({e | e(/) n Mod{P) yf 0},</) 

The set of predictive explanations of P is 

Explp(/, P) = min({e | e(J) C Mod{P)},<i) 

The outcome of the update is defined in terms of the progression of a possible 
world I. 

Definition 8. The progression of an interpretation I is the set 
Prog(7, P) = [J{e(J) n Mod{P) \ e G Expl(J, P)} 
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The progression of an interpretation can be defined also for predictive expla- 
nations. The updated k.b. is defined as the union of all the progressions. 

Definition 9. The result of updating T with P is^ 

Mod{T *abd P) = lJ{Prog(/, P) \ I & Mod{T)} 

In this definition we assume the use of the weak explanations. A similar 
definition can be given using predictive explanations instead. 

We show how the abduction based update can be expressed in AU. We 
assume that all the events are deterministic. This is a natural assumption, since 
the actions of the language MA are always deterministic. Under the assumption 
of determinism, weak and predictive explanations are the same. 

Let E = {ei, . . . , e™} be the set of events. The corresponding action theory 
has m actions A\, . . . , Am ■ The behavioral part of the domain is determined by 
the events in the following manner. For each event ej and interpretation I, if Xi 
is true in ej{I) we have the effect proposition 

Aj causes Xi if A Xk /\ ^Xk 

\xkei xk^i 

otherwise the effect proposition to add is 

Aj causes ^Xi if /\ ^^ ^ /\ 

\xkei xk^i 

The behavioral part Db of the domain description is the union of all these 
effect propositions, for each event e, interpretation / and atom Xi. 

The actual part is composed by two propositions only: 

Da = {T holds at 0, P holds at 1} 

The historical part of the domain description is empty: Dh = 0. The ordering 
is defined as follows. 

Definition 10. The ordering :<a is defined as: {ao,'To, Hq) ^ Hi) if 

and only if 

1 . (Jo = (Jl 

2. <pQ = T>i 

3. it holds eo happens at 0 G Hq, ei happens at 0 G Hi, and eg <ao 

About the correctness of this definition, the following theorem relates the 
entailment in AU and the inference of *abd- 

Theorem 3. For each 3-tuple of propositional formulas T, P, and Q, it holds 
T *ABD P \= Q if and only if D \=a Q holds at 1 (using the ordering Aa), where 
D is the domain description defined above. 

^ In the original Boutilier’s definition, the update is inconsistent if there is an / G 
Modfir) such that Prog(J, P) is empty. For simplicity, we do not consider this case. 
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4 Related Work 

In this section we compare our approach with others that use the similarities 
between reasoning about actions and update. The approach that is most similar 
to ours is the Possible Causes Approach (PCA) proposed by Li and Pereira [8] . 
Although it is based on similar principles, is different from our proposal in two 
aspects. First of all, update is not embedded into the temporal logic. Rather, 
given a domain description and an update, the aim of PCA is to consistently 
incorporate the update in the domain. In our semantics, the updating formula 
is expressed as a proposition of the domain description. 

Another difference regards the KM postulates. Li and Pereira’s approach 
does not obey the KM principle that models of the initial knowledge base must 
be updated separately. This implies, for example, that Winslett’s update cannot 
be easily expressed into Li and Pereira’s formalism. 

The KM postulates, as our framework, provide a generalization of Winslett’s 
approach to update. Due to the lack of space, we cannot make a detailed compar- 
ison between these two frameworks. Let us only say that, while KM postulates 
only generalizes Winslett’s semantics, our approach is more general, as other 
update methods can be encoded in it. 

Another approach which is somewhat related to ours is due to Peppas [10], 
which shows how epistemic entrenchment (a well-known notion in belief revision) 
can be used in the update framework as well. 

The relationship between belief update and reasoning about actions have 
been also analyzed by del Val and Shoham. The key idea of their work can be 
summarized by the following quotation [4] . 

The initial database is taken to describe a particular situation, and the 
update formula is taken to describe the effect of a particular action. 

A formal theory of action is then used to infer facts about the result 
of taking the particular action in the particular situation [...]. Finally, 
anything inferred about the resulting situation can be translated back 
to the timeless framework of belief update. 

Their framework is used to derive a semantics for belief update. In order to 
do this, they translate a specific initial base and an update into a specific theory 
of actions. A single update is translated into a single action. From this point of 
view, our framework is exactly the opposite: we derive a semantics of a possibly 
inconsistent theory of actions by employing the idea of update. An update is 
indeed a fact that holds in some time point, and changes are caused by actions. 

Winslett’s update, as it was initially defined [13], was used in a similar way: 
the initial knowledge base is the state of the world at a certain time point, and 
the update is the effect of a complex action. The result of Winslett’s update is 
used to determine the state of the world after that the action is performed. This 
way the frame problem is solved, if the effect of the action is a conjunction of 
literals. 

In this context, an action is formalized by an update: as have shown, updates 
can be in turns formalized as the result of a number of simpler actions. Following 
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this approach, and using Winslett’s update, a complex action is considered to 
be equivalent to a set of elementary actions, each changing the truth value of a 
variable. In the case of non-disjunctive actions, having yet another solution from 
the frame problem is not really intersting at this point, as many other solutions 
already exist [11, 12]. The point of view offered by this approach may be of 
interest in the case of disjunctive actions. 

5 Discussion 

In this paper we have introduced the language that formalizes scenarios in 
which actions may take place, and of which the agent has no knowledge. The 
language AU is essentially a dialect of the language A for reasoning about actions 
[6] with narratives. 

This formalism is also useful for the field of belief update. Indeed, the defi- 
nitions given by Boutilier, Katsuno and Mendelzon, and Winslett can be easily 
encoded in AU. This provides a way for comparing the semantics of these for- 
malisms. For example, Winslett’s update can be expressed in AU by assuming 
that the change that caused the updating formula to hold in a successive state is 
due to the effect of a sequence of simple actions, each causing the truth value of a 
variable to change. The actions we used to formalize Boutilier’s abduction-based 
update are more complicated (i.e. involving more that one variable). 

Regarding Boutilier’s update, we also note that the translation given here 
is exponential-size. This can be explained by observing that Boutilier’s events 
may be arbitrarily involved. In real scenarios, there should be a simple rule to 
determine the effect of events. 

The language AU allows the integration of many features that are recognized 
by many researchers as fundamental in expressive theories of belief update. 

1. It is possible to express which changes may take place (for example, the fact 
that Fred cannot become alive, once he is dead is formalized by the absence 
of actions that makes Fred alive, if he is dead) . 

2. In some situation, the observation at time I leads to modify our knowledge 
about time 0. This can be expressed in AU. 

3. It is possible to express multiple observations at different time points (iter- 
ated belief update). 

An interesting feature of AU is that it allows inference of happens statements: 
a domain description D implies an happens proposition A happens at t if and 
only if the A happens at t is contained in all the models of D. This issue is 
of course trivial in classical action description languages, in which an happens 
proposition is implied by a domain description if and only if it is in the domain. 
In AU (with the update semantics) it is possible to infer that an action took 
place at time t ii A happens at t is in all the models of the domain description. 

So far for the benefits of this beautiful language AU. Let now turn our atten- 
tion to the possible extensions. A first open problem of this paper is a translation 
from domain description into abductive logic programs (or circumscription). 
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From a semantical point of view, itself can be extended in many ways: 
non-deterministic actions, concurrent actions, and the integration of revision and 
update. 

Consider an extension of with non-deterministic actions. A first appli- 
cation is the incorporation of abduction-based update with non deterministic 
events in our formalism. 

Another benefit regards the treatment of disjunctive information. This is a 
well-known benchmark problem: the initial knowledge base is T = a; A ^y, and 
the update is P = a; 0 y. In such cases, the result of Winslett’s update (as well 
as any other KM update) is T*P = xA^y. This is sometimes correct, but there 
are scenarios in which this result is intuitively wrong. Let for example x be “the 
coin is on the head” , and y be “the coin is on the tail” . According to T, the head 
is currently on the head. When we toss the coin, the knowledge base is updated 
with P = X (B y, that is, what we know is that either the tail is on the head or 
it is on the tail. The result of updating T with P should he T * P = x (By- 

The addition of non-deterministic actions in our framework allows for solving 
such problems. Indeed, what is needed is a non-deterministic action A causes x(B 
y. Note that this is very different from the standard update x (B y happens at n 
(this second scenario gives xA^y as the result of the update). In this formalism it 
is possible to provide enough information to decide whether we are in a situation 
when Winslett’s treatment of disjunctive information is correct, and when it is 
not. This second case is essentially due to the existence of actions whose effect 
is the considered disjunction. 

This use of non-deterministic actions is similar to that of del Val and Shoham 
[4] . However, in their formalism there is no way to distinguish scenarios in which 
the result must be equal to that of Winslett’s update, and when it must be 
different. Indeed, there are scenario in which the result of Winslett’s update is 
correct (i.e. the result of updating T = x A^y with P = x (By must be T * P = 
X A ~^y) and others in which it is not. Del Val and Shoham’s semantics does not 
give any hint on how to make a choice, which is left to the user. On the converse, 
in AU with non-deterministic actions the choice is simply determined by the 
actions that may happen and their effects. Del Val and Shoham’s semantics maps 
both actions and updates into actions, and this leads to a loss of information. 

A second possible extension is the addition of concurrent actions. Consider 
the formalization of Winslett’s update in our framework. There is an action for 
each variable of the alphabet. This is reasonable, since the assumption is that 
the variables can change their value arbitrarily. What is not so intuitive is the 
fact that the observation P is formalized as the value proposition P holds at n. 
Since there is only a knowledge base about the initial time point T, and the 
observation P, there is no intuitive reason of the fact that P holds at 1 does not 
work as well. The technical reason is that the assumption of Winslett’s update 
is that all the changes may happen simultaneously or, still better, between two 
time points it is always possible to perform an arbitrary number of changes. This 
can be expressed in our formalism by introducing concurrent actions. 
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Finally, the principles of AU can be used to extend the system BReLS [9] to 
deal with complex actions. BReLS has been introduced to deal with domains in 
which both revision and update are necessary. The semantics of BReLS are based 
on the principle of combining a measure of reliability of sources of information 
with the likeliness of events. The way in which events are formalized is so far 
quite simple: the only possible actions are those setting the value of a variable to 
a given value (true or false). The user can decide the likeliness of such actions, but 
cannot define more complex actions. Syntactically, this is done with a statement 
like change (i) : I, which means that the penalty (degree of unlikeliness) of 
the literal I becoming true is i. Extending the syntax is quite straightforward: 
change (i) : A means that the penalty of the action A to take place is i. The 
extension of the semantics is also quite easy: a model is composed by a set of 
static models (propositional interpretations), one for each time point, and a set 
of actions for any pair of consecutive time points. This model is consistent with 
the domain description if and only if the static model at time t + 1 is the result 
of applying the actions relative to the pair (t, 1) to the static model of time t. 

The ordering between models can also be obtained by combining the degree of 
reliability of sources with the penalty associated to changes, as usual. Extending 
the implemented algorithms, on the other hand, seems to be not as simple. 
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Abstract. In previous work, we developed a framework for expressing general 
preference information in default logic and logic programming. Here we show 
that the approach of Brewka and Eiter can be captured within this framework. 
Hence, the present results demonstrate that our framework is general enough 
to capture other independently-developed methodologies. As well, since the ex- 
tended logic program framework has been implemented, we provide an imple- 
mentation of the Brewka and Eiter approach via an encoding of their approach. 



1 Introduction 

In previous work [6], we presented a general framework based on default logic for 
expressing general preference information. There, we addressed the problem of repre- 
senting preferences among individual and aggregated properties in default logic. In this 
approach, one begins with an ordered default theory, in which preferences are specified 
on default rules. This is transformed into a second, standard, default theory in which 
the preferences are respected, in the sense that the obtained default extensions contain 
just those conclusions that accord with the order expressed by the original preference 
information. The approach is fully general: One may specify preferences that hold by 
default, or give preferences among preferences, or give preferences among sets of de- 
faults. 

We adapted this approach in [8] for logic programming under the answer set se- 
mantics [11]. While the original approach is usable for full-fledged theorem provers for 
default logic, like DeReS [5], this subsequent approach applies to logic programming 
systems, such as dlv [10] or sinodels [14]. In fact, we have provided an implemen- 
tation of the approach in extended logic programs, serving as a front-end for dlv and 
smodels (see [9] for details). 

In the context of default logic, our methodology involves the appropriate “decom- 
position” of default rules, so that one can detect the applicability conditions of default 
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rules and control their actual application. In our framework, this is carried out within 
a default theory. This is accomplished, first, by associating a unique name with each 
default rule, so that it can be referred to within a theory. Second, special-purpose pred- 
icates are introduced for detecting conditions in a default rule, and for controlling rule 
invocation. This in turn allows a fine-grained control over what default rules are applied 
and in what cases. By means of these named rules and special-purpose predicates, one 
can formalise various phenomena of interest. 

Given an ordered default theory (Z7, W, <), where < is a strict partial order on D, 
the intuition is that one applies the <-maximal default(s), if possible, then the next <- 
greatest, and so on. Thus we adopt a prescriptive interpretation of the ordering, in that < 
prescribes the order in which rules are applied. This can be contrasted with a descriptive 
interpretation, in which the preference order represents a ranking on desired outcomes: 
the desirable (or: preferred) situation is one where the most preferred default(s) are 
applied. 

The approach of Brewka and Eiter [3], first developed with respect to extended logic 
programs and subsequently generalized for default logic in [4], arguably fits the “de- 
scriptive” interpretation. In common with previous work, Brewka and Eiter begin with 
a partial order on a rule base, but define preference with respect to total orders that con- 
form to the original partial order. As well, answer sets or extensions, respectively, are 
first generated and the “prioritized” answer sets (extensions) are selected subsequently. 
In contrast, in our approach, we deal only with the original partial order, which is trans- 
lated into the object theory. As well, only “preferred” extensions are produced in our 
approach; there is no need for meta-level filtering of extensions. 

However, we show here that the approach of Brewka and Eiter is expressible in our 
framework. Consequently, this serves to show the scope and generality of our frame- 
work. As well, this result enables a straightforward implementation of the Brewka and 
Eiter approach. 

In the next subsection we briefly introduce default logic, while Sections 3 and 4 
introduce our approach and Brewka and Eiter’s, respectively. Section 5 describes the 
translation of their approach expressed in default logic, while Section 6 does the same 
for the case of extended logic programs. Section 7 gives brief concluding remarks. 

2 Background 

Default logic [16] augments classical logic by default rules of the form 

oi . (3\ , . . . , I3ji 

1 

where a, (3\, ... , /?„, 7 are sentences of first-order or propositional logic. Here we 
mainly deal with singular defaults for which n = 1. A singular rule is normal if /? is 
equivalent to 7 ; it is semi-normal if (3 implies 7 . [12] shows that any default rule can be 
transformed into a set of semi-normal defaults. We sometimes denote the prerequisite 
a of a default S by Prereq{d), its justification (3 by Justif{6), and its consequent 7 by 
Conseq{6). Accordingly, Prereq{D) is the set of prerequisites of all default rules in 
Z7; Justif{D) and Conseq{D) are defined analogously. Empty components, such as no 




378 



James P. Delgrande, Torsten Schaub, and Hans Tompits 



prerequisite or even no justifications, are assumed to be tautological (we speak in such 
cases of prerequisite-free and justification-free defaults, respectively). Open defaults 
with unbound variables are taken to stand for all corresponding instances. A set of 
default rules D and a set of sentences W form a default theory {D,W) that may induce 
a single, multiple, or even zero extensions in the following way: 

Definition 1. Let (ZJ, W) be a default theory and let E be a set of sentences. Define 
Eq = W and for i > 0.' 



GD, = 

Ei+i = 



Th{Ei) U {Conseq{5) \ 5 € GDi}. 




Then, E is an extension for {D, W) iff E = IJ^g Ei. 

(Th{E) refers to the logical closure of set E of sentences.) Any such extension rep- 
resents a possible set of beliefs about the world at hand. The above procedure is not 
constructive since E appears in the specification of GDi. We define GD{D,E) = 
Ufco generating defaults of extension E. An enumeration {Si)i^i 

of default rules is grounded in a set of sentences W , if we have for every i G I that 
W U Conseq{{So , . . . , k Prereq{6i). 

For simplicity, we restrict our attention in what follows to finite, singular default 
theories, consisting of finite sets of default rules and sentences. 



3 Preference-Handling in Standard Default Logic 

For adding preferences among default rules, a default theory is usually extended with 
an ordering on the set of default rules. In accord with [4], we define: 

Definition 2. A prioritized default theory is a triple (D, W, <) where {D, W) is a de- 
fault theory and < is a strict partial order on D. 

In contrast to [4], however, we use the ordering < in the sense of “higher priority”, i.e., 
S < 6' expresses that S' has “higher priority” than <5. 

The methodology of [6] provides a translation, T, that takes such a prioritized the- 
ory {D, W, <) and translates it into a regular default theory T{{D, W,<)) = {D' , W) 
such that the explicit preferences in < are “compiled” into D' and W' and such that the 
extensions of {D' , W') correspond to the “preferred” extensions of {D, IF, <). More- 
over, the approach admits not only “static” preferences as discussed here — where the 
ordering of the defaults is specified at the meta-level — but also “dynamic” preferences 
within the object language. 

In [6], to begin with, a unique name is associated with each default rule. This is 
done by extending the original language by a set of constants' N such that there is a 
bijective mapping n : D ^ N . We write ns instead of n{5) (and abbreviate nsi by Ui to 
ease notation). Also, for default rule S with name n, we sometimes write n : (5 to render 

' McCarthy effectively first suggested the naming of defaults using a set of aspect functions [13]; 
Theorist [15] uses atomic propositions to name defaults. 
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naming explicit. To encode the fact that we deal with a finite set of distinct default 
rules, we adopt a unique names assumption (UNAa?) and domain closure assumption 
(DCAat) with respect to N. That is, for a name set N = {ni, . . . , nm}, we add axioms 

UNAat : {m ^ Uj) for all rii,nj G N with i ^ j; 

DCAat : \/x. name{x) = (x = ni V • • • V a; = rim)- 

For convenience, we write Va; G N. P{x) instead ofVx. name(x) D P{x). 

Given 5i < Sj, we want to ensure that, before Si is applied, 6j can be applied or 
found to be inapplicable. 

More formally, we wish to exclude the case where Si G GDn but Sj ^ GD„ al- 
though Sj G GDra for some m > n in Definition 1. For this purpose, we need to be 
able to (i) detect when a rule has been applied or when a rule is blocked, and (ii) control 
the application of a rule based on other antecedent conditions. For a default rule 
there are two cases for it to not be applied: it may be that the antecedent is not known to 
be true (and so its negation is consistent), or it may be that the justification is not con- 
sistent (and so its negation is known to be true). For detecting this case, we introduce a 
new, special-purpose predicate bl(-). Similarly we introduce a predicate ap(-) to detect 
when a rule has been applied. To control application of a rule we introduce predicate 
ok(-). Then, a default rule S = is mapped to 

q; A ok(n 5 ) : f3 ok(ni) : ~^a ^(3Aok{ns) ■ 

7Aap(ni) ’ bl(n5) ’ bl(n5) 

These rules are sometimes abbreviated by Sa, Sb-i , Sb ^ , respectively. While Sa is more or 
less the image of the original rule <5, rules Sb^ and Sb^ capture the non-applicability of 
the rule. 

None of the three rules in the translation can be applied unless ok(ni) is true. Since 
ok(-) is a new predicate symbol, it can be expressly made true in order to potentially 
enable the application of the three rules in the image of the translation. If ok(ri 5 ) is true, 
the first rule of the translation may potentially be applied. If a rule has been applied, 
then this is indicated by asserting ap(ni). The last two rules give conditions under 
which the original rule is inapplicable: either the negation of the original antecedent a 
is consistent (with the extension) or the justification f3 is known to be false; in either 
such case bl(ni) is concluded. 

We can assert that default rij : is preferred to rii : in the object lan- 

guage by introducing a new predicate, A, and then asserting that rii A rij. However, 
this translation so far does nothing to control the order of rule application. Nonetheless, 
for Si < Sj we can now control the order of rule application: we can assert that if Sj 
has been applied (and so ap{rij) is true), or known to be inapplicable (and so h\{rij) is 
true), then it is ok to apply Si. The idea is thus to delay the consideration of less pre- 
ferred rules until the applicability question has been settled for the higher ranked rules. 
Formally, this is realized by adding the axiom 

Vx G N. [Vy € N.{x A y) D (bl(y) V ap(y))] D ok(a;) (2) 



to the translation. 
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To summarize, letT((U, VP,<)) = {D,W) he the translation obtained in this way, 
for a given prioritized default theory (ZJ, TH, <). Then, the prioritized extensions of 
(ZJ, TH, <) are determined by the (regular) extensions of (ZJ, TH), modulo the original 
language. 

It is important to note that this translation schema is just one possible preference 
strategy. Changes to the conditions when a default is considered to be applicable (real- 
ized by the specific form of the decomposed defaults 6a: and axiom (2)) result 

in different preference strategies. Also, further rules and special-purpose predicates can 
be added, if needed. For instance, in Sections 5 and 6 we rely on an additional predicate 
ko(-) that aims at eliminating rules from the reasoning process. 

4 Brewka and Eiter’s Approach to Preference 

We now describe the approach to dealing with a prioritized default theory introduced 
in [4]. First, partially ordered default theories are reduced to totally ordered ones.^ 

Definition 3. A fully prioritized default theory is a prioritized default theory (ZJ, W, <) 
where < is a total ordering. 

The general case of arbitrary prioritized default theories is reduced to this restricted 
case as follows. 

Definition 4. Let {D, W, <) be a prioritized default theory. Then, E is a prioritized 
extension of {D, W, <) ijf E is a prioritized extension of some fully prioritized default 
theory {D, W, <') such that <C<'. 

Conclusions of prioritized default theories are defined in ferms of prioritized exten- 
sions, which are a subset of the regular extensions of a default theory, i.e., the extensions 
of (D,W) according to [16]. 

The construction of prioritized extensions relies on the notion of activeness [ 1 , 2] . 
A default <5 is active in a set of formulas S, if (i) Prereq{6) G S, (ii) ^Justif{6) ^ S, 
and (iii) Conseq{6) ^ S hold. Intuitively, a default is active in S if it is applicable with 
respect to S but has not yet been applied. 

Definition 5. Let A — (D, W, <) be a fully prioritized prerequisite-free default theory. 
The operator C is defined as follows: C{A) = IJ^^g Ei, where Eq = Th{W), and for 
every z > 0, 

{ Uj<i ^3 default from D is active in Uj<i 

T/i(Uj<i Ej U {Conseq{6)}) otherwise, where 6 G D is the maximal 

default {w.r.t. <) active in Uj<i ^j- 

In the case of prerequisite-free, normal default theories, the operator C always produces 
an extension in the sense of [16] and thus can directly be used to define prioritized 
extensions: 

^ In fact, [4] deal with so-called well-orderings, which are generalised total orderings, needed 
for treating infinite domains. 
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Definition 6. Let A = {D, <) be a fully prioritized prerequisite-free, normal de- 

fault theory. Then, E is the prioritized extension of A iff E = C{A). 

The next definition addresses the more general class of prerequisite-free theories: 

Definition 7. Let A = (D, W, <) be a fully prioritized prerequisite-free default theory. 
Then, a set E of formulas is a prioritized extension of A iff E = C(A^), where A^ = 
{D^ , W, <) and = D\{S G D \ Conseq{5) G E and ~^Justif{5) G E}. 

That is, A-^ is obtained from A by deleting all defaults whose consequents are in E 
and which are defeated in E. Clearly, this leaves normal rules unaffected. The purpose 
of this filter is illustrated in [4] by the following default theory: 

^3 = ({ : ^,^3 : ^,n4 ^ } ,9,{Sj < \ i < j}) . (3) 

This theory has two regular extensions, Th{{A, B}) and Th{{^A, B}). Applying op- 
erator C to A^ yields the first extension. However, it is argued in [4] that this extension 
does not preserve priorities because default <52 is defeated in E by applying a default 
which is less preferred than 62 , namely default i53. This extension is ruled out by the fil- 
ter in Definition 7 because Th{{A,B}) Th{{^A,B}) = Theory 

A^ has therefore no prioritized extension. 

The next definition accounts for the general case by reducing it to the prerequisite- 
free one. For checking whether a given regular extension E is prioritized, Brewka and 
Eiter evaluate the prerequisites of the default rules according to the extension E. To this 
end, for a default 6 , define <5^ as the prerequisite-free version of 6 , i.e., (5^ results from 
6 by replacing Prereq{S) by T. 

Definition 8. Let A = (D, W, <) be a fully prioritized default theory and E a set of 
formulas. The default theory Ae = {De, W, < e) is obtained from A as follows: 

1. De = {(5^ \ 5 G D and Prereq{5) G E}; 

2. for any Ci, C 2 G De, Ci <e C 2 iff Si < S 2 where Si = max<{(5 G D \ 6^ = Ci}- 

In other words, De is obtained from D by (i) eliminating every default 6 G D such that 
Prereq{S) ^ E, and (ii) replacing Prereq{5) by T in all remaining defaults <5. 



Definition 9. Let A — [D, W, <) be a fully prioritized default theory. Then, E is a pri- 
oritized extension of A, if (i) E is a classical extension of A, and (ii) E is a prioritized 
extension of Ae. 

That is, {ii) is equivalent to E = C{{Ae)^)- 
For illustration, consider [4, Example 4]: 



: A ^ ^ A : B 



(4) 



and where W = %. This theory. A, has two regular extensions: Ei = Th{{A, B}) 
and E 2 = Th{{A,^B}). Ae^ amounts to -^ < 2 ^^ < Clearly, {Aei)^^ = 
Aei- Also, we obtain that C{Aei) = Ei, that is, Ei is a prioritized extension. In 
contrast to this, E 2 is not prioritized. While Ae 2 = Ae^ and {Ae^)^'^ = Ae^, we get 
C{{Ae 2 )^^) = El f E 2 . That is, C{{Ae 2 )^^) reproduces Ei rather than E 2 - 
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This example reveals the difference between the prescriptive methodology of [6] 
discussed in the previous section, and Brewka and Eiter’s descriptive approach dis- 
cussed here, insofar as the former method actually selects no prioritized extension. In- 
tuitively, this can be explained by the observation that for the highest-ranked default 
, neither applicability nor blockage can be asserted: Either of these properties relies 
on the applicability of lesser-ranked defaults, effectively resulting in a circular situation 
destroying any possible extension. Nonetheless, as we show next, the methodology of 
[6] is general enough to admit a suitable preference strategy enforcing the simulation 
of prioritized extensions in the sense of Definition 9. 

5 Prioritized Extensions via Standard Default Logic 

Given an alphabet V of some language C-p, we define a disjoint alphabet V' as V' = 
{p' I p G V} (so implicitly there is an isomorphism between V and V'). Then, for 
a G Cp, we define a' G Lpi as the result of replacing in a each proposition p from 
V by the corresponding proposition p' in V' . This is defined analogously for sets of 
formulas, default rules and sets of default rules. We abbreviate Cp and Lpi by L and 
£', respectively. 

We obtain the following translation mapping prioritized default theories in some 
language L onto standard default theories in the language L° obtained by extending 
£ U £' by new predicates symbols (• •), ok(-), ko(-), bl(-), and ap(-), and a set of 

associated default names: 

Definition 10. Given a prioritized default theory A = (D, W, <) over C and its set of 
default names N = {ns \ S G D}, define Tbe{A) = (ZJ°, W°) over C° by: 

D° = 



W° = 

U 

u 

We denote the second group of rules in (5) by <5°, , and ; those in (6) are abbrevi- 

ated by S^, and 5^, respectively. 

It is important to note that the inclusions D C D° and W C W° hold. As we 
show in Theorem 2, this allows us to construct regular extensions of {D, W) within 
extensions of (D°, W°). Such an extension can be seen as the guess in a guess-and- 
check approach; it corresponds to Condition (/) in Definition 9. 

The salient part of the corresponding check, viz. Condition (if) in Definition 9, is 
accomplished by the second group of rules in (5) and the remaining facts in W°. To- 
gether with W' C W° , the rules of form S° aim at rebuilding the guessed extension in 
£'. They form the prerequisite-free counterpart of the original default theory in £'. In 
fact, the prerequisite of S° refers via a to the guessed extension in £; no formula in £' 
must be derived for applying S°. This accounts for the elimination of prerequisites in 



DU 



ok(n 5 )Ao: : /3,f3' ok(n< 5 ) : ok(n< 5 ) A-i/3A-i/3' : 

7'Aap(n5) ’ bl(n5) ’ bl(n5) 



6=^gd} (5) 






7A^/3: 

ko(rt5) 



,5 = 



Q : (3 



G D 



}u{. 



3x^N. ^ok(a 






u 

W u W 

[ni I (AA2 ) G <}U{DCAat,UNAa,} 

{Va; G N. [Vy G N. ko(y) V [{x ^ y) D (bl(y) V ap(y))]] D ok(a;)} 



(6) 

(7) 

( 8 ) 
(9) 
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Condition (1) of Definition 8. Moreover, the elimination of rules whose prerequisites 
are not derivable is accomplished by rules of form . Rules of form guarantee that 
defaults are only defeatable by rules with higher priority. In fact, it is ^/3' that must be 
derivable in such a way only. 

The application of rules according to the given preference information is enforced 
by axiom (9): For every n,, we derive ok(ni) whenever, for every nj, either ko{rij) is 
true, or, if rii A nj holds, either ap{rij) or b\{rij) is true. This axiom allows us to derive 
ok(nj), indicating that Si may potentially be applied, whenever we have for all Sj with 
S^ < that Sj has been applied or cannot be applied, or Sj has already been eliminated 
from the preference handling process. This elimination of rules is in accord with Def- 
inition 7 and realized by S‘^^. The preference information in (8) is rendered complete 
through rules of form SZ^ . This completion is necessary for the formula in (9) to work 
properly: whenever {Si, Sj) ^ <, rule SZ^ allows us to conclude (in the extension) that 
-^{rii A rij) holds. 

Lastly, (5^ rules out unsuccessful attempts in rebuilding the regular extension from 
C within C according to the given preference information. In this way, we eliminate all 
regular extensions that do not respect preference. 

For illustration, reconsider theory (4), viz. 

ri3 : ^ < ri2 : < ni : 

and W = %. Recall that this theory has two regular extensions: one containing {A, ^B} 
and another containing {A, B}-, but that only the latter is a prioritized extension accord- 
ing to [3]. We get: 

: A : A : B 

A -,B B 

ok{n3) : A,A' ok{n2) ok{ni)AA:B^B' : ^ok(ni)V^ok(n2)V^ok(ri3) 
A'Aap(n3) — iS'Aap(ri2) B'Aap(ni) _L 

ok(ni ) : —iA,—iA' 
bl(ni) 

ok(ri3)A^AA^^' : ok(ri2)ABAB' : ok(ni ) A-iBA^S' : 

bl(n3) bl(n2) bl(ni) 

For brevity, we omit all defaults of form ■ 

First, suppose there is an extension with A and ~^B. Clearly, ^ and contribute 
to such an extension. Having ~^B denies the derivation of ap(ni). Also, we do not get 
bl(ni) since we can neither derive ^B' nor is ~^A consistent. Therefore, we do not 
obtain ok(ri 2 ); thus, ^ok(n 2 ) is consistent and we obtain _L which destroys the putative 
extension at hand. 

Next, consider a candidate extension with A and B. In this case, ^ and 
apply. Given ok(ni) and A, we may derive B' A ap(rii). This gives ok(ri 2 ) and then 
ok(n 2 ) Ai? Ai?', from which we get bl(ri 2 ). Finally, we derive ok(n 3 ) and A' Aap(n 3 ). 
Unlike the above, we cannot derive _L and we obtain an extension containing A and B. 
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For another example, consider the theory obtained from example (3): 



-.A 

A A 



: B 
B 



ok(ni) : —iB ,— iB' ok{ri 2 ) '■ ^A,—^A' 
A'Aap(ni) -'A'Aap(n2) 



ok(n3) : A^A' 
A'Aap(ns) 



ok(n4) : B,B' 
S'Aap(n3) 



ok{ni)ABAB' : ok(n2)AAA4.' : ok(ri 3 ) A^>lA^ A' : ok(ri 4 ) A^SA^B' : 

bl(ni) bl(n 2 ) bl(n^) bf^ns) 

AaB : 
ko(ni ) 



: 3x^N. ^ok(£c) 

I 



While this theory has two regular extensions, it has no prioritized extension under the 
ordering imposed in (3). Suppose there is a prioritized extension containing A and B. 
This yields ko(ni) and then (9) gives ok(ri 2 ). Having A excludes (i52)a. Moreover, we 
cannot apply {S 2 )l^ since A' is not derivable (by higher-ranked rules). We thus cannot 
derive ok(ri 3 ), which leads to a destruction of the current extension through (5^ 

The next theorem gives the major result of our paper. 

Theorem 1. Let A = (D, W, <) be a prioritized default theory over C and E a set of 
formulas over C. 

E is a prioritized extension of A iff E = E f] C and E is a (regular) extension of 
Abe{A). 

In what follows, we elaborate upon the structure of the encoded default theories: 

Theorem 2. Let A = (Z?, W, <) be a prioritized default theory over C and let E° be 
a regular extension ofTsEiA) = (D°, W°). Then, we have the following results: 

1. E° D C is a ( regular) extension of (D, W); 

2. (E° n £)' = E°n£' (or ip G E° ijfip' G E° for ip G £); 

3. S e DnGD{D°,E°) iff 6° G GD{D°,E°); 

4. S e D\GD(D°,E°) iffs° e GD(D° , E°) or 6° eGD(D°,E°); 

5. £ GD(D^ £»)' £ GB(D», B"). ■ 

The last property shows that eliminated rules are eventually found to be inapplicable. 
This illustrates another choice of our translation: instead of using the second group of 
rules in (5), we could have used 



{ oW(n)Aa:0,p',—iko(n) ok(n) : ^a,^a\—iko(n) ok(n)A-'/3A-'/3G ^ko(n) 

7 'Aap(n) ’ bl(n) ’ bl(n) 






Although this renders the derivation of ap(n), bl(n), and ko(n) mutually exclusive, the 
additional justification ^ko(n) is not needed. That is, it is sufficient to remove from 
the preference handling process; the rule is found to be blocked anyway. 

The following theorem summarizes some technical properties of our translation: 

Theorem 3. Let E be a consistent extension ofTsE^A) for prioritized default theory 
A = [D, W, <). We have for all 5,5' & D that 

1. ns <ns' & E iff^{ns ^ ns') ^ E; 

2. ok(n^) G E; 

3. ap(ni) G E iffb\{ns) ^ E. 

The two last results reveal an alternative choice for , namely ■ ^ap(a:)A^bi(a;) ^ 
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One may wonder how our translation avoids the explicit use of total extensions of 
the given partial order. The next theorem shows that these total extensions are reflected 
by the grounded enumerations of the second group of rules in ( 5 ): 

Theorem 4 . Given the same prerequisites as in Theorem 2 , let be some 

grounded enumeration of GD{D° , E°). For all 61,62 G define i 5 i <C 62 iff 

k2 < k\ where kj = min{i G I \ 6° = {6j)°forx G {0,61,62}} fork = 1 , 2 . Then, 
<C is a total ordering on such that ^ C (< n {D^ x 

That is, whenever A = A^ according to Definition 7 , we have that ^ is a total ordering 
on D such that <CC<. 

Finally, one may ask why we do not need to account for the “inherited” ordering 
in Condition 2 of Definition 8. In fact, this is taken care of through the “tags” ap{ns) 
in the consequents of rules 6° that guarantee an isomorphism between D and in 
Definition 8. More generally, such a “tagging of consequents” provides an effective 
correspondence between the applicability of default rules and the presence of their con- 
sequents in an extension at hand. As a side effect, this facilitates the notion of activeness 
in Section 4 by rendering Condition (iii) unnecessary. 



6 Compiling Prioritized Answer Sets 

In this section, we describe how Brewka and Eiter’s preference approach [ 3 ] for ex- 
tended logic programs can be encoded within standard answer set semantics, following 
the methodology developed in [8]. We commence with a recapitulation of the necessary 
concepts. 

As usual, a literal, L, is an expression of the form p or ~^p, where p is an atom. The 
set of all literals is denoted by Lit. A rule, r, is an expression of the form 

Lq < L \, . . . , not 7 /^_i_i, . . . , not (10) 

where n > m > 0 , and each (0 < f < n) is a literal. The symbol “not” de- 
notes negation as failure, or weak negation. Accordingly, the classical negation sign 
is in this context also said to represent strong negation. The literal Lq is called 
the head of r, and the set {Li, . . . , Lm, not Lm+i, • ■ • , not L„} is the body of r. 
We use head{r) to denote the head of rule r, and bodyfr) to denote the body of r. 
Furthermore, let body~^{r) = {Li, . . . , Lm} and body~{r) = {Lm+i, ■ ■ ■ , Ln}. The 
elements of body~^ (r) are referred to as the prerequisites of r. If body^{r) = 0 , then r is 
a prerequisite-free rule', if body{r) = 0, then r is a. fact', if r contains no variables, then 
r is ground. We say that a rule r is defeated by a set of literals X iff body~{r) n A 7^ 0 . 
As well, each literal in body~{r) n A is said to defeat r. We define not X as the set 
{not L \ L G A}. 

A set of literals A is consistent iff it does not contain a complementary pair p, ^p 
of literals. We say that A is logically closed iff it is either consistent or equals Lit. 

A rule base is any collection of rules; an {extended) logic program, or simply a 
program, is a finite rule base. A rule base (program) is prerequisite-free (ground) if all 
rules in it are prerequisite-free (ground). 
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For a rule base R, we denote by R* the ground instantiation of R over the Herbrand 
universe of the language C of R. 

The answer set semantics interprets ground rules of the form (10) as defaults 

Li A ... A . . . , 

Lo 

A set X of ground literals is called an answer set of the ground program P iff X is of 
the form E n Lit, where E is an extension of the default theory obtained by identifying 
each rule r G P as a default of the form (1 1). Answer sets of programs not necessarily 
ground are obtained by taking the answer sets of the ground instantiation P* of P. 

A prioritized logic program is a pair II = (P, <), where P is a logic program and 
< is a strict partial order. Following [3], the ground instantiation of a prioritized logic 
program (P, <) is obtained as follows: Let P* be the ground instantiation of P and 
define r* <* s* for r* ,s* G P* providing r* , s* are instances of r, s G P, respectively, 
such that r < s. If <* is a strict partial order, then the pair (P*, <*) defines the ground 
instantiation of (P, <); otherwise, the ground instantiation of (P, <) is undehned. In 
the sequel, we will be concerned with ground prioritized programs only. 

A fully prioritized logic program is a prioritized logic program (P, <) where < 
is a total ordering. Prioritized answer sets of prioritized logic programs are defined 
similarly to prioritized extensions of prioritized default theories. That is to say, first the 
prerequisite-free case is treated, and afterwards the general case is addressed in terms 
of the prerequisite-free case. 

For fully prioritized ground programs. Definitions 5 and 7 boil down to the fol- 
lowing operator: Let II — (P, <) be a fully prioritized ground prerequisite-free logic 
program, {ri)i^i be an enumeration of the ordering <, and A be a set of literals. Then, 
Cn{X) is the smallest logically closed set of literals containing IJie/ where 

{ Uj<j if P is defeated by IJ^-^ . Ej, or 

head{ri) G X and is defeated by X; 

U {head(ri)} otherwise. 

As in the default logic case, this construction is unique in the sense that for a fully 
prioritized prerequisite-free ground program U, there is at most one answer set A of P 
such that Cn{X) = A (cf. [3, Lemma 4.1]). Accordingly, this set is referred to as the 
prioritized answer set of II, if it exists. Prioritized answer sets of an arbitrary (i.e., not 
necessarily prerequisite-free) ground fully prioritized program II = (P, <) are given 
by sets A of ground literals which are prioritized answer sets of the prioritized program 
IIx = (Pjf, <Jt), where <x is constructed just as the ordering <£; of Definition 8, 
and Px results from P by (i) deleting any rule r G P such that body^{r) % A, and (ii) 
removing any prerequisites in the body of the remaining rules. Lastly, A is a prioritized 
answer set of a ground prioritized logic program (P, <) iff (i) A is a (regular) answer 
set of P and (ii) A is a prioritized answer set of some fully prioritized program (P, <') 
such that <C<'. 

This concludes the review of prioritized answer sets according to [3]; we continue 
with a compilation of this approach in standard answer set semantics. 
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As in Section 5, given a ground prioritized program 77 over language £, we assume 
a disjoint language C containing literals V for each L in L. Likewise, rule r' results 
from r by replacing each literal L in r by L'. We maintain for rules the same naming 
convention as for defaults, i.e., the term serves as name for rule r, similarly writing 
n : r as before. As well, the language £° extends £ U £' by new ground atoms (n^ A 
Us), ok(nr), ko(nr), ry(nr, Ug), b\{rir), and ap(nr), for each r, s in 77. 

Definition 11. Let 77 = (P, <) be a prioritized ground logic program over C such that 
P = {ri , ... , Tfc}. Then, the logic program over C° is given by 

P U UreP'^W U {(ni A n2) ^ \ (ri, ra) € <}, 

where T(r) consists of the following collection of rules, for L € body~^{r), K G 
body~(r), and s G P: 



Oi(r) 


head{r') 4 - 


- ap{rir) 


a-2{r) 


ap(nr) ^ 


- ok(nr), body{r), not body~{r') 


bi{r, L) 


h\{rir) 4^ 


- ok{nr), not L, not L' 


62 (r, K) 


h\{nr) ^ 


- ok{nr),K, K' 


ci(r) 


ok{nr) 4 - 


- ry(nr,Pn),---,ry(nr,PrJ 


C2(r, s) 


ry(nr, rig) 4 - 


- not {nr A ng) 


C3(r, s) 


ry(nr, Ug) 4 - 


- {nr A ng),ap{ng) 


C4(r, s) 


ry(nr, rig) 4 - 


- {nr A ng), bl(ns) 


C5(r, s) 


ry(nr, rig) 


- ko(ns) 


d(r) 


L 4 - 


- not ok{nr) 


e(r, K) 


ko{rir) 4 - 


- head{r), K 



The first group of rules in r(r) expresses applicability and blocking conditions of r 
and contains the counterparts of the defaults 6°, 6'^^, and in Dehnition 10, respec- 
tively. To wit, applicability of r is captured by the two rules ai(r) and a 2 (r), while k 
rules of the form b\{r, L) and b 2 {r, K) detect blockage of r, where k is the number of 
literals in body{r). The second group of rules unfolds axiom (9) and relies on auxil- 
iary atoms ry(-, •) (“ready”), taking care of instantiating the quantihcation over names 
expressed in (9). Finally, rules d{r) and e(r, K) correspond to and <5^, respectively. 
We obtain the following result corresponding to Theorem 1; 

Theorem 5. Let 77 = (P, <) be a prioritized ground logic program over C and X a 
set of literals over C. 

X is a prioritized answer set of II iff X = Y f] C and Y is a {regular) answer set 

ofri,%{n). 

Additionally, given suitable concepts for the present case, analogous results to Theo- 
rems 2, 3, and 4 can be shown. We just note the counterpart of Theorem 3: 

Theorem 6. Let X be a consistent answer set of Tg ^{11) for prioritized logic program 
n = (P, <). We have for all r G P that 

1. ok(n^) e X; 

2. ap(ni) G X iffh\{ns) ^ X. 
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The approach is implemented in Prolog and serves as a front-end to the logic pro- 
gramming systems dlv [10] and smodels [14]. Our current prototype, called pip, is 
available at http : / /www . cs . uni -potsdam . de/~torsten/plp/. This URL 
contains also diverse examples taken from the literature. The implementation differs 
from the approach described here, in that the translation applies to named rules only; it 
thus leaves unnamed rules unaffected. 

For illustration, consider the logic programming counterpart of Example ( 4 ) in the 
syntax of pip : 

b name(l), not -b, a. 

-b name (2), not b. 2<1. 

a name (3), not -a. 3 <2. 

We use (or ‘neg’) for classical negation and ‘not’ (or for negation as 

failure. Furthermore, name ( • ) is used to identify rule names; and natural numbers 
serve as names. Note that our implementation handles transitivity implicitly, so that 
there is no need to specify 3 < 1 . 

This is then translated into the following (intermediate) standard program: 



(1) 


b 


not 


neg b, 


a . 






(2) 


bl : - 


ap ( 1 ) . 








(3) 


ap (1) 


; - 


name ( 1 ) 


, ok (1) , not neg b, 


not neg 


bl, 


(4) 


bl (1) 


; - 


ok (1) , 


neg b, neg bl. 






(5) 


bl (1) 


; - 


ok (1) , 


not a, not al . 






(6) 


ko (1) 


; - 


b, neg 


b. 






(7) 


neg b 


; - 


not b . 








(8) 


neg bl : 


- ap ( 2 ) . 








(9) 


ap (2) 


; - 


name ( 2 ) 


, ok (2 ) , not b, not 


bl . 




10) 


bl (2) 


: - 


ok (2) , 


b, bl . 






11) 


ko (2) 


; - 


neg b, 


b. 






12) 


a : - 


not 


neg a . 








13) 


al : - 


ap ( 3 ) . 








14) 


ap (3) 


; - 


name ( 3 ) 


, ok (3) , not neg a, 


not neg 


al . 


15) 


bl (3) 


: - 


ok ( 3 ) , 


neg a, neg al. 






16) 


ko (3) 


: - 


a, neg 


a . 






17) 


2 < 1 












18) 


3 < 2 












19) 


neg M 


< 


N name (N) , name(M), N < M. 




20) 


N < M 


; - 


name (N) 


, name (M) , name (0) , 


N < 0, 


3 < 


21) 


ok (N) 


; - 


name (N) 


, ry (N, 1) , ry (N, 2) 


, ry(N, 


3) . 


22) 


ry (N, 


M) 


: - name (N) , name (M) , not N 


< M. 




23) 


ry (N, 


M) 


: - name (N) , name (M) , N < M 


ap (M) . 




24) 


ry (N, 


M) 


: - name (N) , name (M) , N < M 


bl (M) . 




25) 


ry (N, 


M) 


: - name (N) , name (M) , ko (M) 






26) 


false 


; - 


name (N) 


, not ok (N) . 







The original rules, viz. ri , r2, and r^, are given by ( 1 ) , ( 7 ) , and ( 12 ) . The addi- 
tional encoding of, e.g., rule ( 1 ) is given by ( 2 ) to ( 6 ) . We append the symbol ‘ 1 ’ 
for priming here, e.g., bl is the primed version of b. In detail, ( 2 ) and ( 3 ) correspond 
to ai(ri) and a2(ri), ( 4 ) and ( 5 ) correspond to 62 (ri, i?) and 6i(ri, 3I), and finally 




A Compilation of Brewka and Eiter’s Approach to Prioritization 



389 



( 6 ) corresponds to e(ri, i3). Rules (19) and ( 20 ) are additional rules enforcing a 
strict partial order. Rules ( 21 ) to (25) account for ci (r) to C 5 (r, s) . Lastly, (26) 
implements d{r) . 

The above program is then refined once more in order to account for some special 
features of dlv and stnodels, like implementation of classical negation ‘neg’ and 
‘false’. Also, an extensional database for rule names is provided. 

Calling one of these provers with the respective input corresponding to the above 
program, we obtain the desired prioritized answer set containing the literals A and B 
(i.e., represented by a and b). 



7 Conclusion 

We have shown how the approach of Brewka and Liter, both with respect to extended 
logic programs [3] and to default logic [4], can be expressed in our general framework 
for preferences [ 6 , 8 ]. On the one hand, this illustrates the generality of our framework; 
on the other hand, it sheds light on Brewka and Eiter’s approaches, since it provides a 
translation and encoding of their approaches into extended logic programs and default 
logic, respectively. As well, our encoding allows a straightforward implementation of 
[3] via a translation into extended logic programs. 

Lastly, we note that our approach described in [ 8 ] used dynamic preference informa- 
tion, in that preferences were expressed within a logic program. As well, in the case of 
default logic, [ 6 ] also describes the incorporation of dynamic preferences. Thus in these 
approaches, preferences can be encoded as holding only in specific contexts, holding 
by default, and so on. Such a dynamic setting was also sketched in [4]. It is a straight- 
forward matter to extend Definitions 10 and 1 1 to handle this dynamic case as well. 
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Abstract. We present a framework for decision making with the possibility to 
express circumstance-dependent preferences among different alternatives for a 
decision. This new formalism. Ordered Choice Logic Programs (OCLP), builds 
upon choice logic programs to define a preference/specialization relation on sets 
of choice rules. We show that our paradigm is an intuitive extension of both 
ordered logic and choice logic programming such that decisions can comprise 
more than two alternatives which become only available when a choice is actu- 
ally forced. The semantics for OCL programs is based on stable models for which 
we supply a characterization in terms of assumption sets and a fixpoint algorithm. 
Furthermore we demonstrate that OCLPs allow an elegant translation of finite ex- 
tensive games with perfect information such that the stable models of the program 
correspond, depending on the transformation, to either the Nash equilibria or the 
subgame perfect equilibria of the game. 



1 Introduction 

Preferences among defaults or alternatives play an important role in nonmonotonic rea- 
soning, especially when modeling the complex way people reason in every day live. In 
case of conflict, humans prefer the default or alternative which provides more reliable, 
more specific or more important information. 

For the last two decades, a lot of research in the nonmonotonic reasoning community 
has concentrated on bringing preference into the different paradigms: for example logic 
programming ([6,9,12]), extended logic programming ([3]), extended disjunctive logic 
programming ([1]) and prioritized circumscription ([7]). We will discuss some of these 
systems in more detail later on in this paper when we compare them to our approach. 
These systems have demonstrated their usage in a wide variety of applications like law, 
object orientation, model based diagnosis or configuration tasks. They are especially 
suitable for working with exceptions to defaults. 

In this paper we present a formalism that enables us to reason about decisions with 
more than two alternatives where the preference between alternatives depends on the 
situation. The systems mentioned above do not support such dynamic preferences: they 
either use the preferences when the model is already being computed, which means that 

* The author wishes to thank the FWO-Vlaanderen for its support. 
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the decisions are already made, or they only support preferences between rules with op- 
posite consequences, leaving out the possibility to have decisions with more than two 
alternatives. Another problem of the latter type of systems is that the alternatives (i.e. 
complementary literals) are hxed even before writing the program. We feel that alterna- 
tives should emerge only when a choice between them is required. Let us illustrate this 
with the following example. 

Example 1 (Tommy’s Birthday). Today it is Tommy’s birthday. Six years old, time goes 
fast. To celebrate this, his mother agreed to invite some of his friends over for a party. 
Sitting in his room he is dreaming about his own private party: “A huge birthday cake 
with lots of candles, of course not forgetting the icing. Lots of candy and biscuits. 
We just have to make sure that there is plenty, you can never have enough treats. But 
no matter what, there dehnitely has to be that big cake. Hopefully my mum will let 
me decide, that way I can have everything my heart desires. I know that if she starts 
interfering, she will force me to choose. That is what mums always do.” 

Intuitively, one would expect two possible outcomes for this party: 

- Tommy’s Birthday, Tommy is planning. Tommy and his friends having cake, bis- 
cuits and candy. 

- Tommy’s Birthday, Tommy’s mother does the planning, Tommy and his friends 
only having cake. 

Thus, in the hrst solution cake,biscuit and candy are not considered alternatives of 
which only one has to be selected, while in second they are because Tommy’s mother 
forces him to make this difficult choice. 

To allow this kind of reasoning, two things need to be added to logic programming. 
First of all we need a mechanism to represent the possible decisions. As argued in [4,5], 
choice logic programs are an intuitive tool to represent conditional decisions, as the 
semantics make sure that only one alternative is chosen. Thus, choice logic programs 
will be the fundaments on which we build our new formalism. Now only a mechanism 
for denoting preference/order amongst different alternatives is missing. To this end, we 
will use a generalization to multiple alternatives of the ideas behind Ordered Logic [6]. 
Our formalism, called Ordered Choice Logic Programs, defines a partial order amongst 
choice logic programs, called components. Each component inherits, like in object ori- 
entation, the rules of the less specific components. Normal model semantics is used 
until alternatives for the same decision are in conflict. Then, the most specific alterna- 
tive is decided upon. 

These extensions offer a new view point to the above mentioned application domains. 
For example it is possible to reason about which method overrides the others in a sub- 
classing chain, where with the previous systems one could only detect whether a method 
was overridden or not. Also applications in AI & law can be envisaged: e.g. lawyer can 
work out a whole strategy by taking into account the possible actions of the other par- 
ties. 

We are also able to add a new application domain to this list: Game Theory^ [8]. We 
will show that ordered choice logic programs are capable of naturally representing fi- 
nite extensive games with perfect information such that the stable models of the former 

* Game Theory has proven its usefulness in domains such as economics and computer science. 
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correspond with, depending on the transformation, either the Nash equilibria or the 
subgame perfect equilibria of the latter. 

The outline of the rest of the paper is as follows: In Sect. 2 we introduce ordered 
choice logic programs. The stable model semantics for such programs is presented in 
Sect. 3. Sect. 4 is used for discussing an application in game theory while Sect. 5 com- 
pares ordered choice logic programs with some alternative approaches. 



2 Ordered Choice Logic Programs 

The basis of Ordered Choice Logic Programs are, as the name already might have indi- 
cated, choice logic programs[4,5]. 

We identify these choice logic program with their grounded version, i.e. the set of all 
ground instances of its clauses. This keeps the program finite as we do not allow func- 
tion symbols (i.e. we stick to datalog). 

Definition 1 ([4,5]). A Choice Logic Program, CLP for short, is a finite set of rules of 
the form A <— B where A and B are finite sets of atoms 

Intuitively, atoms in A are assumed to be xor’ed together while B is read as a con- 
junction (note that A may be empty, i.e. constraints are allowed). In examples, we often 
use “ 0 ” to denote exclusive or, while is used to denote conjunction. 

The Herbrand Base and interpretations for a choice logic programs are defined in 
the usual way, except that we will only consider total interpretations in this paper. 

Definition 2 ([4,5]). Let P be a CLP. The Herbrand Base of P, denoted Bp, is defined 
as the set of all atoms appearing in the program. An interpretation I is any subset of 
the Herbrand Base of P, i.e. I C Bp. An atom in I is assumed to be true while an atom 
in Bp \ I is considered false. We denote the set of all false atoms wrt I as I. 



Definition 3. An Ordered Choke Logic Program, or OCLP, is a pair {C, =^) where 
C is a finite set of choice logic programs, called components, and “=^” is a partial 
order on C. In this paper we assume that C contains a minimal element C± such that 
C± X for all X G C. Furthermore, we assume that a rule appears in at most one 

component ofC^. 

For two components C\,C 2 G C, Ci -< C 2 implies that C 2 contains more general 
information than C\^. Also [A, B] is used to denote the set {X | A AT B}. Simi- 
larly, [A, B[ denotes the set {AT | A AT ^ B}. 

Throughout the examples, we will often represent an OCLP P by means of a directed 
acyclic graph (dag) in which the nodes represent the components and the arcs the rela- 
tion 

^ This is only a technical restriction that considerably simplifies the notation. 

^ As usual, “A” denotes the restriction of “=^” to all the pairs of distinct components. 
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Fig. 1. Tommy’s Birthday Dream. 



Example 2. Tommy’s Birthday dream can easily be translated into the OCLP depicted 
in Fig. 1 where the choice rules in P 4 correspond with Tommy specifically knowing 
that either he or his mother will do the organization and that in case his mother will be 
in charge, he will be forced to choose between all the goodies. The order, together with 
the rules of P 2 and P 3 , expresses that Tommy is more in favor of cake than any of the 
other treats. Finally Pi introduces the general fact that it is Tommy’s birthday. 

As more specihc components “inherit” the rules from more general components, 
we also need, when defining an interpretation, to consider the atoms mentioned in those 
less specific parts. 

Definition 4. Given an OCLP P and a component A G C of P. An interpretation for 
P in A is any interpretation of A*, where A* denotes the CLP {r \ r G B G C and A 
B}. An interpretation for P is called global if it is an interpretation in Cj_. 

We say that a rule r is applicable in I if By C / and that r is applied in I if r is 
applicable and \ Hr H /| = 1^. 

We argued in the introduction that choice rules represent a choice between the head 
elements once the precondition, the body, is satisfied (e.g. the rule is applicable). From 
that moment on, we can consider those elements as alternatives. With this we can define 
the alternatives for an atom a from a viewpoint B known in a specific component A, 
called horizon, as those atoms that appear together with a in the head of an applicable 
choice rule in a component C at least as specific as B but not more so than A (e.g. 
Cg[A,B]). 

Definition 5. Let P be an OCLP, let A, B G C be components of P and let I be an 
interpretation in A. Lor any rule r G A* , we use c(r) to denote its component. The set 
of all alternatives for an atom a G Ba* in [A, B], wrt I, denoted 17^^ b](o), is defined 
as: 

^[A B](®) = {b\^r G A* ■ c{r) g[A,B] A Br C I A a,b G Hr with a b} . 

* For a rule r = Q ■<— R,we use Hr to denote its head Q while Br denotes its body R. 

^ I A| denotes the number of elements in the set A. 
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Now we are in a position to demonstrate that OCLPs are really dynamic when con- 
sidering the alternatives for a decision. 

Example 3. Reconsider Tommy’s Dream OCLP of example 2. Let I and J be the fol- 
lowing global interpretations: / = {birthday, me} and J = {birthday, mother} The 
set of alternatives for biscuit in [Cj_, P 2 ] wrt I equals: p^-^{biscuit) = 0, while 

the one wrt J is p^] ( biscuit) = { cake, candy}. In words, this means that biscuits 
is not part of any decision when considering I, while it is if you are using J instead. 

Deciding upon different alternatives can vary depending on the one who is making 
the decision or on the kind of decision. In all cases, when one alternative is preferred 
over all others, the choice is easily made: you simply take that alternative and leave out 
the others. But what happens if some alternatives are equally preferred (or incompara- 
ble)? One possible way of dealing with this dilemma is just making an objective choice 
between those alternatives. In this case, one is at least sure that there is a solution to the 
problem. This is the credulous® way of looking at the world. 

In this context we say, intuitively, that a rule is defeated if there exist(s) some applied 
rule(s) containing head alternatives that are not less preferred than the ones defeated in 
the head of the defeated rule. 

Delinition 6. Let P be an OCLP, let A £ C be a component of P and let I be an 
interpretation in A. A rule r G A* is defeated in A wrt I iff 

\/a G Hr • 3r' G A* ■ c(r) -f c{r') A r' is applied A Hr' 

The rules r' are called defeaters. 



The following two examples illustrate the two possible ways that a rule can be 
defeated: a rule can either be defeated by a single rule containing only alternatives for 
each head element, or by a number of rules containing only alternatives for some of the 
head elements, but together they offer alternatives for the whole lot. 

Example 4. Consider the following OCLP (C, =^) with: 

Pi : ri : a ^ P 2 : r 2 : a 0 5 <— P 3 : rs : b ^ 

such that C = {Pi, P2, P3} and P3 A P2 A Pi. Let I = {6} be an interpretation in 
P3. For this interpretation, the rule ri is defeated by the more specihc rule rs as a has a 
more specific alternative 6, due to the more specific rule r 2 . 



® There exists also a more skeptical way of facing alternatives that are equally preferred or in- 
comparable. Whereas in the credulous approach a choice between the alternatives is acceptable, 
one remains undecided in the skeptical one. Although most results in this paper also hold for 
the skeptical semantics, we will only use the credulous approach in this paper. 
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Example 5. Consider the following OCLP (C, =^) with: 

Pi : ri : a 0 6 ^ P2 '■ a ^ P3 : : b ^ 

such that C = {Pi, P2, P3}, P3 0 P2 and P3 ^ Pi. Assume the global interpretation 
I = {a, b}. The atoms a and b are alternatives of each other in [Pi, Pi] wrt I and T2 
and r3 together defeat ri in P3 wrt I Notice also that r3 does not defeat T2, as a and b 
are no longer alternatives in [P3, P2]. 

A model for a program P in a component A is an interpretation that satisfies every 
rule in one way or another. We extend the usual satisfaction criteria for choice logic 
programs with the possibility that rules may also be defeated in order to be satisfied. 

Definition 7. Let P be an OCLP and let A & C be a component of P. An interpretation 
I in A is a model in A iff every rule in A* is either not applicable, applied or defeated 
in A wrt I. A model is global iff it is a model in C_\_- 



Example 6. The program of example 2 has two global models, which correspond to the 
intuition given in example 1, namely: Mi = {birthday, candy, biscuits, cake, me} 
and M2 = {birthday, cake, mother}. 

Facing a decision, one expects that, for obtaining a solution (model), a choice has 
to be made among the available alternatives. 

Proposition 1. Let P be an OCLP and let M be a model for P in a component A £ C. 
Lor every applicable rule r £ A* : 

\/a € Hr ■ a e M \/ {3b G ^ ^ 

3 The Stable Model Semantics 

The simple semantics presented in the previous section is not always intuitive, as is 
illustrated by the following example. 

Example 7. Consider the following OCLP P: 

Pi:a05<— P2 '■ a ^ b 

b ^ a 



with P 2 ^ Pi . 

This program has a single global minimal model M = {a,b}. Note that the presence of 
either o or 6 in M depends on the application of the defeated rule a 0 6 

In this section, we will present the so-called stable model semantics which, while 
preserving minimality, will prevent unnatural models such as the one in example 7 
Just as stable models for “normal” logic programs and disjunctive logic programs, 
our stable models are based on the notion of a Gelfond-Lifschitz transformation. 
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Definition 8. Let M be an interpretation for an OCLP P in a component A. We define 
the Gelfond-Lifschitz transformation for P in A wrt M, denoted P^ , as the positive 
logic program with constraints obtained from A* in the following way: 

1. remove all defeated rules from A*, 

2. remove all false atoms from the head of the remaining rules with more than one 
atom in the head, 

3. replace all rules r with more than one head atom with constraint rules: for each 
such rule r where a,b € Hr and a b, we add a constraint 

^ Br, a, b . 

The introduction of constraints is necessary to assure that a non-defeated applicable 
choice rule with more than one head atom will be properly satisfied (i.e. only one head 
atom must be considered true). 

Stable models for a program are then minimal models of the program obtained from 
applying the Gelfond-Lifschitz transformation. 

Definition 9. Let M be an interpretation for an OCLP P in a component A. M is 
called a stable model for P in A iff M is a minimal model for the positive logic program 

r>M 

■ 

In example 6, both Mi and M 2 are stable. 

The next theorem confirms our earlier claim that the stable model semantics restricts 
the minimal model semantics. 

Theorem 1. Let M be a stable model for an OCLP P in a component A. Then, M is 
minimal model for P in A. 

The reverse is not true, as illustrated by the following example. 

Example 8. Consider the program P from example 7 which has a unique minimal 
model M = {a, 6} in P 2 - Applying the Gelfond-Lifschitz transformation on P in P 2 
yields 

M . 

■ b^ a 

This program has as a minimal model 0 M, so M is not stable. 

Looking back on example 7, we note that, for the minimal model M = {a, 6}, at 
least one atom must have been produced only by a defeated rule. Intuitively, such atoms 
can be considered assumptions, because they lack a proper motivating rule to introduce 
them. The following definition makes this intuition more precise. 

Definition 10. Let I be an interpretation for an OCLP P in a component A. A set 
X C Ba* is called an assumption set wrt I iff for each a € X one of the following 
conditions is satisfied: 

1. 3r= {a (BA-^B)g A* - BClAAnlf^ibAr is not defeated in A wrt I; or 

2. 3r = (^*^ B,a) ■ B I; or 
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3. Vr S A* where a G Hr, one of the following conditions holds: 

(a) Br ^ I; or 

(b) BrOX 0; or 

(c) r is defeated in A wrt I; or 

(d) HrnBrfib . 

The set of all assumption sets for P in A wrt I is denoted Ap\a{I)- The greatest as- 
sumption set for P in A wrt I, denoted QAS p\a{I), is union of all assumption sets 
for P in A wrt I. 

The first condition in Definition 10 expresses that, if there exists a non-defeated appli- 
cable rule with already a true atom in the head, then the interpretation does not need a 
to become/maintain a model. The second condition says that, if a constraint contains, 
besides the element one is considering, only true atoms, one should not assume that 
element to be true as well. The last condition states that if every rule with a in the head 
is either not applicable, defeated, containing assumptions in the body or sharing atoms 
both in the head and the body, then we know that the atom a is not involved in making 
the interpretation into a model. 

The greatest assumption set is an assumption set. 

Proposition 2. Let I be an interpretation for an OCLP P in a component A. Then, 
QASp\a{I) G Ap\a{I)- 

Assumption sets can be used to eliminate candidate models. 

Proposition 3. Let M be a model for an OCLP P in a component A. Then M is an 
assumption set, i.e. M G Ap\a{M). 

Checking the assumption-free property can be quite time consuming when one 
needs to verify every subset of Ba* ■ The following proposition implies that there is 
an easier way. 

Proposition 4. Let I be an interpretation for an OCLP P in a component A. I is 
assumption-free, i.e. ICQAS p\a{I) = iff no non-empty subset of I is an assumption 

set for P in A wrt I. 

Assumption sets characterize stable models. 

Theorem 2. Let M be a model for an OCLP P in a component A. Then, M is stable 
iff M is assumption-free for P in A wrt M, i.e. M H QASp\a{J^) = 0- 

For choice logic programs we have that minimal models are unfounded-free, which 
equals assumption-free when the interpretation is total. For OCLP, this can no longer 
be maintained. A counter example was presented in example 7: the minimal model 
{a, b} is not assumption-free (i.e., {a, b} G Ap{{a, 5})). 

Assumption sets are also useful to compute stable models: Fig. 2 contains a sketch 
of a backtracking fixpoint procedure BF such that BF{%) generates all stable models (in 
the component A). 
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procedure BF{I :set<atom>) { 
set<atom> X = QASp\a{I) 

if (X n /) / 0 

fail 

if (X = 7) 

/ is a stable model 

else { 

set<rule> R = {r \ r £ A* applicable and not defeated and Hr 0 7 = 0} 
set<atom> J = {a \ a£ Hr f\r£Rf\a^X} 

for each a £ J 

BF{I\j{a}) 

} 

} 



Fig. 2. Computing stable models 



4 An Application to Finite Extensive Games with Perfect 
Information 

In this section we give a brief and informal overview of extensive games with perfect 
information ([8]) and demonstrate in more detail how OCLP’s can be used to retrieve 
the games’ equilibria from the transformed programs. 

An extensive game is a detailed description of a sequential structure representing 
the decision problems encountered by agents (called players) in strategic decision ma- 
king (agents are capable to reason about their actions in a rational manner). The agents 
in the game are perfectly informed of all events that previously occurred. Thus, they 
can decide upon their action(s) using information about the actions which have already 
taken place. This is done hy means of passing histories of previous actions to the decid- 
ing agents. Terminal histories are obtained when all the agents/players have made their 
decision(s). Players have a preference for certain outcomes over others. Often, prefe- 
rences are indirectly modeled using the concept of payoff 'fthe.re players are assumed to 
prefer outcomes where they receive a higher payoff. 

Summarizing, a game is 4-tupple, denoted (TV, 77, P, (>i)ig at), containing the players 
N of the game, the histories 77, a player function P telling who’s turn it is after a certain 
history and a preference relation >i for each player i over the set of terminal histories. 
For examples, we use a more convenient representation: a tree. The small circle at the 
top represents the initial history. Each path starting at the top represents a history. The 
terminal histories are the paths ending in the leafs. The numbers next to nodes repre- 
sent the players while the labels of the arcs represent an action. The number below the 
terminal histories are payoffs representing the players’ preferences (The first number is 
the payoff of the first player, the second number is the payoff of the second player, ...). 

Example 9. Two people use the following procedure to share two desirable identical 
objects. One of them proposes an allocation, which the other either accepts or rejects. 
In the event of rejection, neither person receives either of the objects. 

An extensive game with perfect information , (TV, 77, P, (>i)ig n), that models the in- 
dividuals’ predicament is shown in its alternative representation in Fig. 3. 
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Fig. 3. The Sharing-an-Object game of example 9. 



A strategy of a player in an extensive game is a plan that specihes the actions chosen 
by the player for every history after which it is her turn to move. A strategy profile 
contains a strategy for each player. E.g. ((2, 0), yyy) is a strategy prohle where the first 
player intends to take both objects and the second player plans to accept (indicated by 
“y”) any of the three possible proposals from the first player. 

The hrst solution concept for an extensive game with perfect information ignores the 
sequential structure of the game; it treats the strategies as choices that are made once 
and for all before the actual game starts. A strategy profile is a Nash equilibrium if no 
player can unilaterally improve upon his choices. Put in another way, given the other 
players’ strategies, the strategy stated for the player is the best this player can do^. 

Example 10. The extensive game with perfect information of example 9 has nine Nash 
equilibria: ((2, 0),yyy), ((2, 0), yyn), ((2, 0), yny), ((2, 0), ynn), ((1, 1), nyy), 

((1, 1), nyn), ((0, 2), nny), ((2, 0), nny), ((2, 0), nnn) . 

The following transformation will be used to retrieve the Nash equilibria from the 
game as the stable models of the corresponding OCLP. 

Definition 11. Let {N, H, P, (>i)ig n) be a extensive game with perfect information. 
The corresponding OCLP P„ can be constructed in the following way: 

- C = {C*} U {C„ I G TV, h G Z • M = Ui{h)}; 

- < CuforallCu G C; 

- yCu, Cw & C ■ Cu < Cw iffu > w; 

-yhe{H\Z)- ({a I ha £ H} ^ ) G C‘; 

- Vh = h\ah 2 £ Z ■ a ^ B £ Cu with B = {h £ [/i]^ | h = h^bhi,P{hf) 
i} and u = Up(^h^){h) . 

The set of components consists of a component containing all the decisions that 
need to be considered and a component for each payoff. The order amongst the compo- 
nents is established according to their represented payoff (higher payoffs correspond to 
more specific components) with the decision component at the bottom of the hierarchy 

^ Note that the strategies of the other players are not actually known to i, as the choice of strat- 
egy has been made before the play starts. As stated before, no advantage is drawn from the 
sequential structure. 

* We use [h] to denote the set of actions appearing in a sequence h. 
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Fig. 4. The corresponding P„ and Pg OCLPs of the extensive game with perfect infor- 
mation of example 9. 



(the most specific component). Since Nash equilibria do not take into account the se- 
quential structure of the game, players have to decide upon their strategy before starting 
the game, leaving them to reason about both past and future. This is reflected in the 
rules: each rule in a payoff component is made out of a terminal history (path from top 
to bottom in the tree) where the head represents the action taken when considering the 
past and future created by the other players according to this history. The component 
of the rule corresponds with the payoff the deciding player would receive in case the 
history was carried out. 

Example 11. Reconsider the Object-sharing game of example 9. The corresponding 
OCLP Pn is depicted on the left side of Fig. 4®. This program Pn has nine stable models 
which exactly correspond with the nine Nash equilibria of the game. 

In the next theorem we show that there is indeed a correspondence between Nash 
equilibria and stable models. 

Theorem 3. Let G = {N, H, P, (>i)ieAr) be a finite extensive game with perfect in- 
formation and let Pn be its corresponding OCLP. Then, s* is a Nash equilibrium for G 
iff s* is a global stable model for Pn. 

Although the Nash equilibria for an extensive game with perfect information are 
intuitive, they have, in some situations, undesirable properties due to not exploiting the 
sequential structure of the game. These undesirable properties are illustrated by the next 
example. 

® To make the graph more readable we renamed the actions (2, 0), (1, 1) and (0, 2) as respec- 
tively o, b and c. We also labeled the responses of the second player to make the choices 
disjoint. 
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Child 




Fig. 5. The Child-Parent game of example 12. 



Example 12. The game in Fig. 5 has two Nash equilibria: (Good, Punish) and (Bad, Not 
Punish), with payoff profiles (1,2) and (2,1). The strategy profile (Good, Punish) is an 
unintuitive Nash equilibrium because given that the Parent chooses Punish after history 
Bad, it is optimal for the Child to choose Good at the start of the game. So the Nash 
equilibrium is sustained by the “threat” of the Parent to choose Punish if the Child is 
Bad. However, this threat is not credible since the Parent has no way to commit herself 
to this choice. Thus the Child can be confident that the Parent will Not Punish him 
in case he is Bad; since the Child prefers the outcome (Bad, Not Punish) to the Nash 
equilibrium (Good, Punish), he has thus the incentive to deviate from the equilibrium 
and choose Bad. We will see that the notion of a subgame perfect equilibrium captures 
these considerations. 

Because players are informed about the previous actions they only need to reason 
about actions taken in the future. This philosophy is represented by subgames. A sub- 
game is created by pruning the tree in the upwards direction. So, intuitively, a subgame 
represent a stage in the decision making process where irrelevant and already known 
information is removed. 

Example 13. The two subgames of the game presented in example 12 are depicted in 
Fig. 6. 




Fig. 6. The subgames of the Child-Parent game of example 13. 



Instead of just demanding that the strategy profile is optimal at the beginning of the 
game, we require that for a subgame perfect equilibrium the strategy is optimal after 
every history. In other words, for every subgame, the strategy profile, restricted to this 
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subgame, needs to be a Nash equilibrium. This can be interpreted as if the players revise 
their strategy after every choice made by them or an other player. 

Example 14. The Child-Parent game of example 12 has one subgame perfect equili- 
brium, (Bad, Not Punish), corresponding to the non-credible threat of the Parent. 

The Object-sharing game of example 9 has two subgame perfect equilibrium : 
{{2,0),yyy) and {{1,1), nyy). 

The following transformation makes sure that suhgame perfect equilibria corres- 
pond with the stable models of an OCLP. 

Definition 12. Let {N, H, P, (>i)ieAr) be an extensive game with perfect information. 
The corresponding OCLP Pg can be constructed as follows: 

- c = {C*} U {C„ I G TV, h G Z • M = U^{h)}; 

- < CuforallCu G C; 

- yCu, Cw & C ■ Cu < Cyj iffu > w; 

-yhe{H\Z)- ({a I ha e H} ^ ) G C‘; 

- \/h = h\ah 2 G Z : P{hi) = i • (a <— S) G Cm with B = {b G [h2] \ h = 
h^bh 4 ., P{hf) i} and u = Up(^h.^){h) . 

This transformation is quite similar to the one for obtaining the Nash equilibria. 
The only difference between the two is the creation of history-dependent rules: since 
subgame perfect equilibria take the sequential structure into account, players no longer 
need to reason about what happened before their decision. They can solely focus on the 
future. 

Example 15. Consider once more the object- sharing game of example 9. The corre- 
sponding OCLP Pg is show on the right side of Fig. 4. This Pg has the subgame perfect 
equilibria {a, yij/ 22 / 3 ) and (6, niy 2 yf) as its stable models. 



Theorem 4. Let G = {N, H, P, (>i)ig n) be a extensive game with perfect informa- 
tion and let Pg be its corresponding OCLP. Then, s* is a subgame perfect equilibrium 
of G iff s* is a global stable model for P. 

Note that [10] proposes an alternative formalism to model strategic games using an 
extension of logic programming. However, in [10], the specihcation of choices is ex- 
ternal to the program while, in our approach, we rely on nondeterminism (and priority) 
to represent alternatives and on the properties of the stable model semantics to obtain 
equilibria. 



5 Relationships to Other Approaches 

5.1 Ordered Logic ([6]) 

Ordered logic programs are a special, also semantically, case of OCLP’s: all choices are 
restricted to 2 alternatives a and ^a. This is confirmed by the following. 
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fly ^ bird 
Pi y penguin ^ 



P 2 0 bird 



penguin 



Pz O -^fly -f— penguin 

(a) 



fly ^ bird 
Pi Lfl penguin <— 



P 2 O bird 



penguin 



Pz O fly ^ ^fly 

(b) 



penguin 



Fig. 7. a) The Ordered logic version of the Penguin problem, b) The corresponding 
Penguin OCLP Pp^ wrt component P 3 . 



Proposition 5. Let P = {C, =^) be an ordered logic program in the sense of [6] and let 
A G C be a component for it. The corresponding OCLP Pa with respect to A equals 
(C', =^) where: 

C' = {B & C \ B f A\ U {A U {a 0 ~^a < — | a, € Ba* }} • 

An interpretation I in A is a model for P in A iff I is a model for Pa in A. 

We illustrate this construction with the following well-known example: 

Example 16 (Tweety, the penguin). The left side of Fig. 7 depicts the ordered logic 
program for the problem. The right hand side gives the corresponding OCLP wrt to 
component P 3 . Both programs have only one model in component P 3 , namely M = 
{ bird, ^fly, penguin}. 

5.2 Other Approaches to Preference 

Dynamic preference in extended logic programs is introduced in [3] in order to obtain a 
better suited well-founded semantics. Although preferences are called dynamic they are 
not dynamic in our sense. Instead of defining a preference relation on subsets of rules, 
preferences are incorporated as rules in the program. Moreover, a stability criterion 
may come into play to overrule preference information. Another difference with our 
approach is that the alternatives are static. 

A totally different approach is proposed in [12]. Here the preferences are defined 
amongst atoms. Given these preferences, one can combine them to obtain preferences 
for sets of atoms. Defining models in the usual way, the preferences are then used to 
filter out the less preferred models. That way, this system is not convenient for decision 
making as the preferences cannot easily be made to depend on the situation. 

In [1], preference in extensive disjunctive logic programming is considered. As far 
as overriding is concerned the technique corresponds rather well with our skeptical 
defeating, but alternatives are fixed as an atom and its (real) negation. 

Outside the context of logic programming, [2] proposes to add priorities to the ob- 
ject language of default logic. Extensions are then required to be compatible with this 
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information. OCLP and [ 2 ] support different intuitions on the notion of priority, as 
shown by the following example^®: 

Example 1 7 . 



Pi : a <— P2:^c<— 

P3 : c ^ a P4 : c 0 ->c ^ 

with P4 P3 0 P2 0 Pi. With our approach, we obtain {a, c} as the (stable) model 
of this program while [2] returns {a, ->c} as the extension for the default theory. [2] 
considers the knowledge of a coming from a more general rule insufficient (the rule 
from Pi) to favor the rule from P4 over the one from P3. We , and also [ 11 ], prefer to 
say that there is no counter evidence for a so we should exploit this knowledge as much 
as possible. 
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